lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <CAHKpqwaq2RxLLYwB3MpSFkPJjkcwxRvbkR9gsoyfEMMQJcqdQg@mail.gmail.com> Date: Mon, 22 Apr 2013 12:41:30 +0200 From: Michał Błaszczak <blaszczakm@...il.com> To: bugtraq@...urityfocus.com Subject: [SQLi] vBilling for FreeSWITCH vBilling for FreeSWITCH. http://blaszczakm.blogspot.com/2013/04/vbilling-freeswitch-sqli.html Michal Blaszczak 1) SQL Injection reset password any SIP account file: controllers/customer.php $sql2 = "UPDATE directory_params SET param_value = '".$new_password."' WHERE directory_id = '".$record_id."' "; 2) SQL Injection http://vbilling-host/customer/edit_customer input Firstname: zuo’;-- (example) Michał Błaszczak http://blaszczakm.blogspot.com