PHPWebThings 1.4 "msg" and "forum" SQL injection
a script by rgod at http://rgod.altervista.org
* hostname (ex: www.sitena me.com)
* path ( ex: /phpwebthings/ or just / )
* action: HASH to see admin username and MD5 password hash, CMD to launch commands, PATH to disclose full application path
full path to www, need this for "INTO OUTFILE" statements (ex.: C:\\\www\\\sit e\\\, /www/site/, or with backslashes from MySQL data directory: ../../www/site/ )
specify a command, cat wt_config.php to see database username & password
specify a table prefix other than the default (wt_)
specify a port other than 80 ( default value )
send exploit through an HTTP proxy (ip:port)