exploit-db-mirror/platforms/php/webapps/18110.txt
Offensive Security 31a21bb68d DB: 2016-09-03
14 new exploits

Too many to list!
2016-09-03 05:08:42 +00:00

28 lines
1,007 B
Text
Executable file

*####################################################################
[+] Exploit Title : CMS 4.x.x Zorder (SQL Injection Vul)
[+] Author : Kr4L BeNiM
[+] Contact : www.facebook.com/kr4l.hacker
[+] Date : November 13, 2011
[+] Software Link: http://mambo-developer.org
[+] Category: Web Apps
####################################################################
Vulnerability:
*SQL injection Vulnerability*
[#] Exploit : -
The "zorder" parameter was not properly sanitized upon submission to
the administrator/index2.php url, which allows attacker to conduct
SQL Injection attack.
[#] Explaination : -
http://server/mambo/administrator/index2.php?limit=10&order[]=11&boxchecked=0&toggle=on&search=sqli&task=&limitstart=0&cid[]=on&zorder=
(SQL Inj Codes)
####################################################################
[+] Greets : Likuid Sky, Hax.Root, S.O.G, DjArs HaXoR, KiLLerMiNd, CyberLeeTs
####################################################################