lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20060309195727.20291.qmail@securityfocus.com> Date: 9 Mar 2006 19:57:27 -0000 From: liz0@...mail.com To: bugtraq@...urityfocus.com Subject: n8cms 1.1 & 1.2 version Sql İnjection And XSS ----------------------------------------------------------------- n8cms 1.1 & 1.2 version Sql İnjection And XSS Site:http://www.nathanlandry.com Demo:http://www.nathanlandry.com/n8cms_v1.1/ Credit : Liz0ziM webpage:www.biyosecurity.com Mail :liz0@...mail.com -------------------------------------------------------------------- 1)Sql İnjection http://[target]/path/?dir=[sql] http://[target]/path/?dir=home&page_id=[sql] 2)Xss [ Cross Site Scripting ] http://[target]/path/?dir=[xss] http://[target]/path/?dir=home&page_id=[xss] http://[target]/path/mailto.php?userid=[xss] ---------------------------------------------------------------------- Source: http://www.blogcu.com/Liz0ziM/307940/ http://biyosecurity.be/bugs/n8cms.txt