+ ----------------------- +
| Banana Dance CMS + Wiki |
+ ----------------------- +
Defect Web-App: Banana Dance CMS + Wiki
Defect type: SQLi
Author: Aodrulez. www.2cto.com Email: f3arm3d3ar@gmail.com
Test Platform: Ubuntu 10.04
: Http://www.doyoubananadance.com/functions/dl.php? File = 4e84e50f89bf7
+ --------- +
| Technical log |
+ --------- +
1] SQLi
Example: http://www.bkjia.com/user. php? Id = 1' [sqli]
Error:
------
Error analysis:
SELECT 'key', 'value' FROM 'bd _ user_data 'WHERE 'user _ id' = '1''
Error: You have an error in your SQL syntax; check the manual
That corresponds to your MySQL server version for the right
Syntax to use near ''1''' at line 1
+ ---------- +
| MalCon |
+ ---------- +
(International Malware Conference)
The CFP for MalCon-2011 is ON!
If you think you are good enough, try cracking our
'Capture the Mal Challenge-2011 'online.
Open to everyone!
For more details, visit malcon.org
Reference
"Microsoft is not the answer. Microsoft is the question. NO is the answer."-Erik Naggum