|
|||||||||||
|
New Advisory: X-script GuestBook
From: <m2x(at)inbox.ru>
Date: Mon Oct 01 2007 - 09:12:40 EDT
--------------------Summary---------------- -----------------Description--------------- Vulnerable script: mes_add.php Parameters 'name', 'email', 'icq', 'website' is not properly sanitized before being used in SQL query. This can be used to make SQL queries by injecting arbitrary SQL code. Condition: magic_quotes_gpc = off --------------PoC/Exploit---------------------- --------------Solution--------------------- --------------Credit----------------------- This archive was generated by hypermail 2.1.8 : Sun Oct 28 2007 - 06:18:40 EDT |
||||||||||
|
|||||||||||