[Juno_okyo's Blog] ChangUonDyU Advanced Statistics - SQL injection
Hiển thị các bài đăng có nhãn vBulletin. Hiển thị tất cả bài đăng
Hiển thị các bài đăng có nhãn vBulletin. Hiển thị tất cả bài đăng
Thứ Bảy, 3 tháng 11, 2012
Thứ Hai, 29 tháng 10, 2012
vBulletin 2.2.7/2.2.8 HTML Injection Vulnerability
Source: http://www.securityfocus.com/bid/6337/infoProblems with vBulletin could make it possible for an attacker to inject arbitrary HTML in vBulletin forum messages. |
vBulletin 2.0.x/2.2.x members2.php Cross Site Scripting Vulnerability
source: http://www.securityfocus.com/bid/6246/infoDue to insufficient sanitization of user supplied values, it is possible to exploit a vulnerability in VBulletin. By passing an invalid value to a variable located in 'members2.php', it is possible to generate an error page which will include attacker-supplied HTML code which will be executed in a legitimate users browser. |
vBulletin 2.0/2.2.x Memberlist.PHP Cross Site Scripting Vulnerability
source: http://www.securityfocus.com/bid/6226/infovBulletin does not filter HTML tags from URI parameters, making it prone to cross-site scripting attacks. |
As a result, it is possible for a remote attacker to create a malicious link containing script code which will be executed in the browser of a legitimate user, in the context of the website running vBulletin. |
vBulletin 2.0/2.2.x Cross Site Scripting Vulnerabilities
Source: http://www.securityfocus.com/bid/5997/infovBulletin does not filter HTML tags from URI parameters, making it prone to cross-site scripting attacks. |
vBulletin 2.0.3 Calendar.PHP Command Execution Vulnerability
Source: http://www.securityfocus.com/bid/5820/infoA remote command execution vulnerability has been reported for vBulletin. The vulnerability is due to vBulletin failing to properly sanitize user-supplied input from URI parameters. |
An attacker can exploit this vulnerability to execute malicious commands on the vulnerable system. |
http://www.example.com/calendar.php?calbirthdays=1&action=getday&day=2001-8-15&comma=%22;echo%20'';%20echo%20%60<command>%20%60;die();echo%22 |
where <command> signifies a command to be executed on the system.Nguồn: http://www.exploit-db.com/exploits/21874/
Thứ Bảy, 27 tháng 10, 2012
Chèn Backdoor vào VBB nhanh-gọn-nhẹ-hiệu quả
Hello, hnay DuyK sẽ hướng dẫn các bạn cách chèn 1 “cửa sau” vào VBB nhanh-gọn-nhẹ-hiệu quả:
Khi bạn đã login vào được admincp của 1 forum vbb nào đó, bạn muốn để lại 1 “cửa sau” trên website này 1 cách kín đáo nhất ?
Đọc thêm »
Khi bạn đã login vào được admincp của 1 forum vbb nào đó, bạn muốn để lại 1 “cửa sau” trên website này 1 cách kín đáo nhất ?
Đọc thêm »
Thứ Sáu, 26 tháng 10, 2012
[TUT] SQLi - Login AdminCP - Deface with XSS
* Tutorial khai thác "ChangUonDyU - Advanced Statistics SQL injection", truy vấn lấy hash để bypass AdminCP, Deface sử dụng XSS.
* Download: http://www.mediafire.com/?1jk4j6wan1v7lie
* Password: (Only Juno_okyo's Blog Members).
* Download: http://www.mediafire.com/?1jk4j6wan1v7lie
* Password: (Only Juno_okyo's Blog Members).
Đăng ký:
Bài đăng (Atom)