Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  SQL Injection In Script VBZooM V1.12

From:underwater_(at)_itdefence.ru <underwater_(at)_itdefence.ru>
Date:30.06.2007
Subject:WheatBlog 1.1 RFI/SQL Injection

Found by E.Minaev (underwater@itdefence.ru)
ITDefence.ru

1) SQL Injection in login function. With help of this injection is possible to make per-symbol brute of tables names of
blog's database (magic_quotes_gpc should be tured off).

------------------------------------------
"$sql = "select * from $tblUsers where login = '$login'";
if ( $login      != $row['login'] )     $valid_user = 0;
               if ( $password  != $row['password'] ) $valid_user = 0;"
------------------------------------------

2) Remote File Inclusion (RFI)
/includes/sessions.php?wb_class_dir=shell?

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server