The OpenNET Project
 
Search (keywords):  SOFT ARTICLES TIPS & TRICKS SECURITY
LINKS NEWS MAN DOCUMENTATION


SQL injection in phpWebThing 1.4.4


<< Previous INDEX Search src Set bookmark Go to bookmark Next >>
Date: 11 Nov 2005 11:45:49 -0000
From: [email protected]
To: [email protected]
Subject: SQL injection in phpWebThing 1.4.4
X-Virus-Scanned: antivirus-gw at tyumen.ru

Vulnerable: phpWebThings 1.4.4
website : http://phpwebthings.org

The bug in download.php

ThE Exploit :

http://www.target.com/download.php?file=|SQL


ThE Error:

You have an error in your SQL syntax. Check the manual that corresponds to your MySQL server version for the right syntax to use near 'order by date DESC' at line 1

AhLaM
http://www.lezr.com/vb
Best Regards ,,,


<< Previous INDEX Search src Set bookmark Go to bookmark Next >>



Партнёры:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
Хостинг:

Закладки на сайте
Проследить за страницей
Created 1996-2025 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру