about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , DUware DUforum Multiple SQL Injection Vulnerabilities


Title DUware DUforum Multiple SQL Injection Vulnerabilities
Published 2005-06-22-12:00AM
Updated 2005-06-22-07:03PM
Class Input Validation Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  dedi dwianto <the_day@echo.or.id> is credited with the discovery of this vulnerability.
Vulnerable  DUware DUforum 3.1
Not Vulnerable  
Code   No exploit is required.

The following proof of concept URI are available:
http://www.example.com/DUforum/messages.asp?iMsg=[SQL Inject]248&iFor=6
http://www.example.com/DUforum/post.asp?iFor=6[SQL Inject]
http://www.example.com/DUforum/forums.asp?iFor=[SQL Inject]
http://www.example.com/DUforum/admin/userEdit.asp?id=[SQL Inject]
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 09:20:50 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
/search/ex zoosex.com www.sexe.c menhu.sksz bbs.skszx. bolly wood Sinhalanka sindhu4u.c www.worlds www.skszx. Marco anto prctl www.jjwxc. www.sexe.c HUMAN ANIA p...p=1.ht www.skszx. sex movies buke8.com. sex-89 www.sex xx GNU debonair b www.skszx. www.peking phpnuke ad phpbb+2.08 www.875.gd Www.sex.co www.soszx. dance orie commonsens Mail Serve All bolywo WWW.NAMITH www.skszx. www.hdy1.c video porn Www.pinkwo www.charw. proftpd 1. Remote+Roo bbs.xtklyy maxcpm.inf www.femdom F-prot Www.pinkwo %2Fsearch% doodhwali naked Sani