OneOrZero Helpdesk V1.6.4.1 susceptible to SQL injection and XSS
Date: 15 Aug 2006 10:57:33 -0000
From: [email protected]
To: [email protected]
Subject: OneOrZero Helpdesk V1.6.4.1 susceptible to SQL injection and XSS
X-Virus-Scanned: antivirus-gw at tyumen.ru
vendor:
http://www.oneorzero.com/
vuln :
http://[host]/supporter/index.php?t=tupd&id=[SQL]
http://[host]/supporter/index.php?t=tupd&id=[XSS]
Author : Vampire
[email protected]
Homepage : Www.HackerZ.iR
Www.H4ckerZ.Com
Iran HackerZ Security Team