首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
SimpleBlog version 2.1 is susceptible to SQL injection
来源:http://www.hackerscenter.com 作者:Zinho 发布时间:2006-01-19  

SimpleBlog version 2.1 is susceptible to SQL injection and cross site scripting attacks due to a lack of variable sanitization.

Hackers Center Security Group (http://www.hackerscenter.com/)
Zinho's Security Advisory

Risk: High


- Note from the author
Simple Blog is a free weblog application intended for personal use. The
latest version, 2.1, features xhtml/css template structure, rss feed, blog
calendar and an easy to use control panel.
http://www.8pixel.net


SimpleBlog 2.1 suffers of non-existent user input sanitization so it's
possbile to insert html code and to inject sql.
It is possible to get admin's password without modifying any database
and without having any privilege.

I will post only one sample of sql injection and one for xss. Many other
are present.

SQL Injection:
/simpleblog/?view=archives&month='&year=2006

XSS:
comments.asp allows for html code to be inserted as comment.

-- HSC Security Group
Get your site audited for free and pay only if we find it vulnerable!
www.securityforge.com

Security researcher? http://www.hackerscenter.com/security


====>
Webmaster of
Hackers Center
Internet Security Portal and Research group
http://www.hackerscenter.com

Free Security Audit of your site:
http://www.hackerscenter.com/security
http://www.securityforge.com/web-hosting



 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·VERITAS NetBackup Volume Manag
·eyeBeam handling SIP header DO
·Xmame 0.102 (-lang) Local Buff
·Eterm LibAST Configuration Eng
·Farmers WIFE version 4.4 sp1 f
·SquirrelMail Change Passwd Plu
·HomeFTP versions 1.1 and below
·imap4d Buffer Overflow
·Microsoft Windows Metafile (WM
·mIRC Font Buffer Overflow
·Serial Line Sniffer Buffer Ove
·Cisco Aironet Wireless Access
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved