Likes Likes:  0
Resultaten 1 tot 2 van de 2
Geen

Onderwerp: SQL IN PortailPHP

  1. #1
    ABDUCTER_MINDS@YAHOO.COM
    SQL IN PortailPHP
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    SQL IN PortailPHP


    Class: Input Validation Error
    CVE: CVE-MAP-NOMATCH
    Remote: Yes
    Local: yes
    Credit: ABDUCTER ---> ABDUCTER_MINDS@YAHOO.COM [OR] ABDUCTER_MINDS76@HOTMAIL.COM
    Vulnerable: PortailPHP 2.4 and all version
    ***************************************

    info :- PortailPHP POWERFUL FORUM AND formal site http://www.portailphp.com/
    there is sql in index.php
    ***************************************

    discussion :- sql in indwx.php make an error in database and appear full path informathion like
    that (Warning: mysql_result(): Unable to jump to row 0 on MySQL result index 34 in /home/httpd/vhosts/***/httpdocs/portailphp/mod_forum/read_mess.php on line 14)
    ****************************************

    exploit:- index.php?affiche=Forum-read_mess&id=[sql]
    example http://www.victim.com/portailphp/ind...-read_mess&id='
    *****************************************
    CREDITS :- FOR ALL ARAB {EGYPT}
    WWW.S4A.CC
    TO MY LOVE (N0N0)

  2. #2
    Steven M. Christey
    SQL IN PortailPHP
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: SQL IN PortailPHP


    >Vulnerable: PortailPHP 2.4 and all version


    According to the vendor web site, the most recent version of
    PortailPHP is 1.3, released in October 2004.

    Was this a typo?

    Other reports for SQL injection in an "id" parameter for 1.3 were
    publicly made by CENSORED on May 21, 2005, but those reports were for
    other modules (News, File, Liens, and Faq). A casual source code
    inspection of version 1.3 suggests that these are distinct bugs.

    - Steve

Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics