Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Woltlab Burning Board info_db.php multiple SQL injection |
|---|---|
| Date: | 26 Oct 2005 14:01:28 -0000 |
################################################################# # # Woltlab Burning Board info_db.php multiple SQL # injection # ################################################################# ->discovered by [R] Vendor: "Trooper" URL: www.wbbcoderforum.de Version: <= 2.7 Type: SQL-injection Description: ------------------------ Info-DB is a very powerful and popular download-module with many features. Information: ------------------------ Info-DB is prone to multiple SQL injection vulnerabilities. (It's possible to upload any files through info_db.php.) Bug: ------------------------ [1] /info_db.php?action=file&fileid=[SQL-Injection] [2] /info_db.php?action=file&fileid=59&subkatid=[SQL-injection] Both tested on 2.5. All other versions should be vulnerable, too. An exploit-code is available at rootbox.cx.la/batznet.com Patch: ------------------------ No Patch available. Greetz: ------------------------ greetz fly out to 2lm, Lux2, redice, triple6, darkkilla, EaTh // written by [R] // www.batznet.com
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Looking for a security contact at Macrovision/InstallShield, Richard M. Smith |
|---|---|
| Next by Date: | Secunia Research: Mantis "t_core_path" File Inclusion Vulnerability, Secunia Research |
| Previous by Thread: | Looking for a security contact at Macrovision/InstallShield, Richard M. Smith |
| Next by Thread: | Secunia Research: Mantis "t_core_path" File Inclusion Vulnerability, Secunia Research |
| Indexes: | [Date] [Thread] [Top] [All Lists] |