lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20060814150148.20874.qmail@securityfocus.com> Date: 14 Aug 2006 15:01:48 -0000 From: vampire_chiristof@...oo.com To: bugtraq@...urityfocus.com Subject: Virtual War v1.5.0 SQL injection and XSS Virtual War v1.5.0 SQL injection and XSS http://[host]/vwar/war.php?s=[SQL] http://[host]/vwar/war.php?page=[SQL]or[xss] http://[host]/vwar/war.php?showgame=[SQL] http://[host]/vwar/war.php?sortby=[sql] http://[host]/vwar/war.php?sortorder=[sql] http://host]/vwar/calendar.php?year=[xss] vendor: www.vwar.de google:"Powered by: Virtual War v1.5.0" Discovered by Vampire Connect Me : Vampire_chiristof@...oo.com