RW-Download is an upload and Download system that supports templates and multilingual versions. Index. php of RW-Download 4.0.6 has the SQL injection vulnerability, which may cause leakage of sensitive information.
[+] Info:
~~~~~~~~~
// * Title | => RW-Download v4.0.6 => (index. php) SQL Injection Vulnerability
// * Secript | => RW-Download
// * Language | => Php
// * Download | |=> http://traidnt.net/vb/attachment.php? Attachmentid = 72765 & d = 1157806602
// * Date | => 2011-01-30
// * Version | => 4.0.6
// * D0rk | => "Powered by RW-Download v4.0.6"
// * Info | => By Dr. Net, Abdullah hacker team, | My Email: xdr.netx@Gmail.com
[+] Poc:
~~~~~~~~~
// | => Http: // localhost/index. php? Dlid = 1 <={ SQL Injection}
// * Admin Page
// | => Http: // localhost/admin. php
[+] Reference:
~~~~~~~~~
Http://www.exploit-db.com/exploits/16080
Fix:
No other, only Filter