about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , aflog Multiple SQL Injection and Cross-Site Scripting Vulnerabilities


Title aflog Multiple SQL Injection and Cross-Site Scripting Vulnerabilities
Published 2008-01-22-12:00AM
Updated 2008-01-24-11:47PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  shinmai is credited with the discovery of these vulnerabilities.
Vulnerable  aflog.org aflog 1.01
Not Vulnerable  
Code  An attacker can exploit these issues via a browser. To exploit a cross-site scripting vulnerability, the attacker must entice a victim to follow a malicious URI.The following example URI is available: http://www.example.com/aflog/comments.php?id='+UNION+SELECT+666,null,concat('username:',username,',password:',password),1,null,1+FROM+members+ORDER+BY+id+DESC+LIMIT+1/*
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 16:07:05 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
components remote 2.6 /search/ex components 200 /compo php hackin 200+%252Fc %252Fadmin qdqy.5d6d. www.kl998. photo iran www sexi c www.sexy g zoosex golf+cart+ Apache htt www.bjbm.o 4899 Apache htt Apache htt www.Arbic Free3gpsex Apache htt SSH-2.0-Op SVN rs gallery news for C sexy boob www.txtwan t520t mambo Remo Videos ana a...etup[u hot girls Www.indea. www.xdbyf. 31038 Www.18to19 animal wit ASPPlaygr news for c super x aishwarya maxcpm.inf modules/vw searchgall video-seve www.rrms36 8650 vidio porn