about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Advanced Guestbook Password Parameter SQL Injection Vulnerability


Title Advanced Guestbook Password Parameter SQL Injection Vulnerability
Published 2004-04-23-12:00AM
Updated 2005-02-12-09:53PM
Class Input Validation Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  Discovery is credited to JQ <idiosyncrasie@xs4all.nl>.
Vulnerable  Advanced Guestbook Advanced Guestbook 2.2
Not Vulnerable  Advanced Guestbook Advanced Guestbook 2.3.1
Code   No exploit is required. The following proof of concept exploits have been provided:

JQ <idiosyncrasie@xs4all.nl> explains that it is possible to trigger this issue by leaving the username entry blank and entering the following string in the password field:

') OR ('a' = 'a

Spy Hat <spyhat@spyhat.com> comments that it is also possible to leverage this issue by leaving the password field blank and entering the following string into the username field:

? or 1=1 --
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Tue, 15 Dec 2009 10:59:47 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
mbtwt.2008 06014 freeSSHd n.../error aotocad200 www.ogrish www.firedj maxcpm.inf www.90jj.c SQL Inject DNS Poison Crack+Data insvible+b Juegos de 1 2 all dmoz.im livese mapeng.net www.591xmm Indian sex Tagger LE. Video+sex+ Tagger LE. Sex+in+uk WWW.ZTOD.C 200 /compo mbtwt.2000 www,sex. wwsexyphot Sex18.com video sxe Www.Sexmo Tagger LE. Tagger LE. nayandara. pictures o www.lamstw dianyeng.j php-...224 Www.s& news/explo blog.sina. WWW.SIR LA Www.world. sexcy+pic Free hot p Malavikaph news for c BREASTS Indian+Ido