Parameter x is not properly sanitized before being used in SQL query. This
can be used to evaluate arbitrary SQL expression.
Condition: magic_quotes_gpc = off
2. Multiple Cross-Site Scripting.
Vulnerable Script: index.php
Parameters autor, www, temat, tresc are not properly sanitized. This can be
used to post arbitrary HTML or web script code.
3. PHP Code Insertion.
Administrator has an ability to edit variable values from config.php file.
This can be used to insert arbitrary PHP code into config file which
executes by every php-script.
System access is possible.
Condition: magic_quotes_gpc = off
--------------PoC/Exploit----------------------
Available at: http://evuln.com/vulns/111/exploit.html
--------------Solution---------------------
No Patch available.
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Microsoft Device IO Control wrapped by the iphlpapi.dll API shipping with Windows Vista 32 bit and 64 bit contains a possibly exploitable, buffer overflow corrupting kernel memory.