<<< Date Index >>>     <<< Thread Index >>>

PhxContacts <= 0.93.1 beta Multiple SQL injection & xss



[+]PhxContacts
[+]website of software:http://www.phoetux.net/
[+]founded by Morocco Security Team 
[+]special 10x to:all friends ww.lezr.com & www.cim-team.org
[+]xss
[+]http://[target]/login.php?m=[xss]
[+]SQL
[+]http://[target]/carnet.php?view_cat=&all_lines=true&motclef=[sql]
[+]http://[target]carnet.php?view_cat=2&nbr_line_view=[sql]
[+]http://[target]/contact_view.php?id_contact=[sql]
[+]have nice day