about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Advanced Guestbook Password Parameter SQL Injection Vulnerability


Title Advanced Guestbook Password Parameter SQL Injection Vulnerability
Published 2004-04-23-12:00AM
Updated 2005-02-12-09:53PM
Class Input Validation Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  Discovery is credited to JQ <idiosyncrasie@xs4all.nl>.
Vulnerable  Advanced Guestbook Advanced Guestbook 2.2
Not Vulnerable  Advanced Guestbook Advanced Guestbook 2.3.1
Code   No exploit is required. The following proof of concept exploits have been provided:

JQ <idiosyncrasie@xs4all.nl> explains that it is possible to trigger this issue by leaving the username entry blank and entering the following string in the password field:

') OR ('a' = 'a

Spy Hat <spyhat@spyhat.com> comments that it is also possible to leverage this issue by leaving the password field blank and entering the following string into the username field:

? or 1=1 --
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Mon, 07 Dec 2009 19:08:26 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Free Sex f delta.html &amp;a MySQL 4.1. Www varisi 200 /compo Crack+Data AMember.h brk2 C ww.lmdby.c www.tt5868 www.592gg. None 1.0.1 None WWW.duguay uhuyh. 200 /compo Web Wiz Fo None Solaris+ma None None None None ProFTPD 1. None girls hump Banglore s ww xnxx.co Sakila sex ww xnxx.co www.wg4g.c /component 200 /compo _1componen Play sex remote roo openssl 0. www.shxin. www.babess Free sexs sex sxx www.pbxoa. news for c 200 /compo arab girl Fuckinphot bahoon.com