BugTraq
Oxynews Sql İnjection Mar 16 2006 07:42PM
r00t3rr0r gmail com
Oxynews Sql İnjection

Website:http://www.oxynews.net/

Demo:http://www.scriptevi.com/files/demo/news/oxynews/
-------------------------------------------------------------------
Credit:R00t3RR0R

Website:www.biyosecurity.be / www.biyo.tk

mail: r00t3rr0r (at) gmail (dot) com [email concealed]
-------------------------------------------------------------------
Bug:

http://victim.com/oxynews/index.php?oxynews_comment_id=[sql]

--------------------------------------------------------------------

Google:"News managed with OxyNews © 2002"

--------------------------------------------------------------------
Source:
http://www.blogcu.com/Liz0ziM/363710/
http://biyosecurity.be/bugs/oxynews.txt

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus