lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20060511210603.13826.qmail@securityfocus.com> Date: 11 May 2006 21:06:03 -0000 From: sn4k3.23@...il.com To: bugtraq@...urityfocus.com Subject: phpBB "charts.php" XSS and SQL-Injection // phpBB "charts.php" (hack) XSS and SQL-Injection // ----------------------------------------------------------------- [~] Advisory by: LoK-Crew [-] Exploit: http://www.example.com/charts.php?action=vote&rate=1&id=[XSS] http://www.example.com/charts.php?action=vote&rate=1&id=[SQL] [-] Googledork: inurl:"charts.php" "powered by phpbb" [+] Visit: www.LoK-Crew.de