Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:12087
HistoryApr 05, 2006 - 12:00 a.m.

ArabPortal 2.0.1 Stable [ 9 CrossSiteScripting & 1 SQL Injection ] MultBugz

2006-04-0500:00:00
vulners.com
8

ArabPortal Bugs :-

    ArabPortal 2.0.1 Stable [ 9 CrossSiteScripting & 1 SQL Injection ] MultBugz

    BugTraqz :- D3vil-0x1 | Devil-00
    Visit Palestine :- www.palestineonly.com

/*

    1- /forum.php?action=view&id=1&cat_id=3&adminJump=D3vil-0x1[HTML - XSS ]
2- /forum.php?action=view&id=1&cat_id=3&forum_middle=D3vil-0x1[HTML - XSS ]

//*
    3- /forum.php?mineID=[SQL Injection]
*//

4- /members.php?action=changepass&form=D3vil-0x1[HTML - XSS ]
5- /members.php?action=edit&form=D3vil-0x1[HTML - XSS ]
6- /pm.php?action=reply&form=D3vil-0x1[HTML - XSS ]
7- /pm.php?action=sendmsg&form=D3vil-0x1[HTML - XSS ]
8- /mail.php?action=sendpage&form=D3vil-0x1[HTML - XSS ]
9- /mail.php?action=sendtome&form=D3vil-0x1[HTML - XSS ]
10- /mail.php?action=sendtousers&userid=1&form=D3vil-0x1[HTML - XSS ]

*/