about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , PHP-Nuke Web_Links Module Multiple SQL Injection Vulnerabilities


Title PHP-Nuke Web_Links Module Multiple SQL Injection Vulnerabilities
Published 2005-04-07-12:00AM
Updated 2005-04-07-05:51PM
Class Input Validation Error
CVE   CAN-2005-0997
Remote  Yes
Local  No
Credit  Discovery of these vulnerabilities is credited to Maksymilian Arciemowicz <max@jestsuper.pl>.
Vulnerable  Francisco Burzi PHPNuke 7.6
Not Vulnerable  
Code   No exploit is required.

The following proof of concepts are available:
http://www.example.com/[php-nuke]/modules.php?name=Web_Links&l_op=modifylinkrequestS&url='[SQL]
http://www.example.com/[php-nuke]/modules.php?name=Web_Links&l_op=viewlink&orderby=[SQL]&min=[SQL]
http://www.example.com/[php-nuke]/modules.php?name=Web_Links&l_op=search&query=sex&orderby=[SQL]&min=[SQL]&show=[SQL]
http://www.example.com/[php-nuke]/modules.php?name=Web_Links&l_op=MostPopular&ratenum=[SQL]&ratetype=num
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sat, 19 Dec 2009 08:55:48 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
video sex apache con port 7.htm www.zgmaim drftpd 200 /compo opensolari phpMyAdmin youngersex news for c Www.Japan asala actre incest vid popup_wind news for c apache 2 0 ass neighb article free movie www.brides news for c Brute For sav remote Video amat ACS diamond WWW.PORNOR Www.dudhwa news for C cid remote www.zgmaim sexthai www.zgmaim lead.html/ Funi www.videos www.wd42.c black ice news for c 200 /compo superzooi wwwsexvide zz.5i.com runcms CMS is Fre Chicassexi www..Xxxgi news for c hasdies