lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Date: Sat, 27 Nov 2010 08:41:41 -0700 From: u6q@...mail.com To: bugtraq@...urityfocus.com Subject: SQL injection and Path Disclosure Auth Bypass in 4images 1.7.X -----------Summary----------- eVuln ID: 200 Software: "Powered by 4images" Vendor: PHP Web Scripts Version: 4images 1.7.X dork: "Powered by 4images" Critical Level: medium Type: SQL injection and Path Disclosure Status: Unpatched. No reply from developer(s) PoC: Available Solution: Not available Discovered by: ahmed atif ( http://7ria.com/ ) site: http://www.7ria.com/ --------Description-------- bug exists in categories.php script. Warning: mysql_num_rows(): supplied argument is not a valid MySQL result resource in /home/xxx/html/hootersflorida/includes/db_mysql.php on line 116 --------PoC/Exploit-------- PoC code is available at: http://www.site.com/4images/categories.php?cat_id=1&page=-2999+%27%29+union/ ---------Solution---------- Not available ----------Credit----------- Vulnerability discovered by Ahmed Atif