about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , PHPFreeNews SearchResults.PHP Multiple SQL Injection Vulnerabilities


Title PHPFreeNews SearchResults.PHP Multiple SQL Injection Vulnerabilities
Published 2005-08-17-12:00AM
Updated 2005-08-17-08:56PM
Class Input Validation Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  h4cky <www.h4cky0u.org> is credited with the discovery of these vulnerabilities.
Vulnerable  PHPFreeNews PHPFreeNews 1.40
Not Vulnerable  
Code   No exploit is required.

The following proof of concept URI are available:
http://www.example.com/phpfn/SearchResults.php?Match='&NewsMode=1&SearchNews=Search&CatID=0
http://www.example.com/phpfn/SearchResults.php?Match=1&NewsMode=1&SearchNews=Search&CatID='
http://www.example.com/phpfn/SearchResults.php?Match=%27&NewsMode=1&SearchNews=Search&CatID=0
http://www.example.com/phpfn/SearchResults.php?Match=1&NewsMode=1&SearchNews=Search&CatID=%27
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sat, 21 Nov 2009 10:51:44 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www yhaoo. www.mmpill Web Wiz Si Glamarouss www.hlccc. Sexycilips ww.xxx.g E-commerce www.haoae. Www.asiase elijijabet www.gzxing 3did.cn Sex giral w`ww`sex`c www.89con php-nuke%2 mambo Remo I would lo pinsou.com SSH-2.0-Op Xxx.pono.c www.oldout cazzi gros www.234cc. news for c PHPX bigbuttss. server ser Nakewome search/exp IIS6.0/ elijijabet www.ltesti Sex giral news for c yong porn pinsou.com INDIASAX.C allonkia Fack photo Sex girls ip board 2 news for c sanianudep anglene jo INVISION 2 siteminder port 7.htm www.live98