# Coder : baltazar a.k.a b4ltazar < b4ltazar@gmail.com> # # CMS name : Plum CMS # Site : http://www.plum-design.net && http://www.plum.rs # # Dork : Powered by PlumDesign # : Powered by PlumDesign site:.rs # : Powered by PlumDesign site:.com # # Admin panel : N/A # # Vulnerability : Sites design with Plum CMS suffers from blind SQL injection # # Vuln parameters : publikacije.php?publCatID=[blind] # : katalog.php?catID=[blind] # : strana.php?pID=[blind] # : reference.php?cID=[blind] # : katalog.php?prodID=[blind] # : galerija.php?albumID=[blind] # : index.php?publ_aricleID=[blind] # # Table : cms_user # Columns : username, password # # Default admin logins : # User : mika : 51fabd9de617b73d0c105c7511bdc03f and cfee398643cbc3dc5eefc89334cacdc1 # : guja : 70f94bafc8dadfb9e4898dd93aab6ef6 # # # Special greetz to my friend sinner_01 # greetz for d3hydr8, qk, marezzi, fx0, TraXdata, v0da, MikiSoft, Soul and all members of ex darkc0de.com, ljuska.org and x0rg.org