[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

SePortal 2.5 SQL Injection

Author
Don
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-17255
Category
web applications
Date add
09-12-2011
Platform
php
############################################################################
# Exploit Title: SePortal 2.5 SQL Injection
# Google Dork: Powered by SePortal 2.5
# Date: Decembar/08/2011
# Author: Don (BalcanCrew & BalcanHack)
# Software Link: http://seportal.org
# Version: 2.5
# Tested on: LiteSpeed
############################################################################
 
Vulnerability:
http://server/redirect.php?action=banner&goto= (SQL)
 
How to fix this vulnerability:
Filter metacharacters from user input.
 
~Don 2011



#  0day.today [2024-12-26]  #