Home page logo
/

bugtraq logo Bugtraq mailing list archives

iwebnegar is vulnerable to all kind of sql injections
From: shervin khaleghjou <oil_karchack () yahoo com>
Date: 15 Dec 2004 15:28:53 -0000



----------------www.karchack.com----------------
----------------www.karchack.net----------------
describtion :
iwebnegar is farsi weblog software written in php 
http://iwebnegar.co.sr

---------

vulnerabilities :
all files seems to be vulnerable such as comments.php , index.php and also administrator login page
-------------

proof of concept :
for example you can use this link to inject the sql server
http://site/weblog/index.php?string=[sql injection code]
----------------


www.karchack.com
www.karchack.net


  By Date           By Thread  

Current thread:
  • iwebnegar is vulnerable to all kind of sql injections shervin khaleghjou (Dec 16)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]