XOOPS WF_Downloads module 2.05 SQL Injection
a script by rgod at http://rgod.altervista.org
* hostname (ex: www.sitename.com)
* path ( ex: /xoops/ or just / )
* username
* ...and password, to retrieve a session cookie
* action: "HASH" to disclose admin loginname & MD5 password hash, "CMD" to launch commands
path to WWW ftom Mysql directory,need this for "...INTO OUTFILE ..." statement (default: ../../www)
specify a table prefix other than the default (fXZtr_)
specify a port other than 80 (default value)
a Unix command, example: ls -la to list directories, cat /etc/passwd to show passwd file, cat ./../mainf ile.php to see database username and password
send exploit through an HTTP proxy (ip:port)