Bug: OneOrZero Helpdesk V1.6.4.1 susceptible to SQL injection and XSS (WLB-2006080157 Ascii Version)

English Version
WLB2

CVE WLB2

 Topic: OneOrZero Helpdesk V1.6.4.1 susceptible to SQL injection and XSS
 Credit: Vampire
 Date: 2006.08.28
 CWE: CWE-89 (Show similar)
 CVE: CVE-2006-4351 (Show details)
CVE-2006-4350 (Show details)

Use CVE to see details like:
- CVSS2,
- Affected Software,
- References

Risk
Local
Remote
Medium
No
Yes

vendor:

http://www.oneorzero.com/

vuln :

http://[host]/supporter/index.php?t=tupd&id=[SQL]

http://[host]/supporter/index.php?t=tupd&id=[XSS]

Author : Vampire

vampire_chiristof (at) yahoo (dot) com [email concealed]

Homepage : Www.HackerZ.iR

Www.H4ckerZ.Com

Iran HackerZ Security Team

[ ASCII VERSION ]

Copyright 2012, cxsecurity.com