Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Re: Authentication bypass, sql injections and xss in ArticleLive 2005
From: "Steven M. Christey" <coley () mitre org>
Date: Tue, 10 May 2005 21:42:17 -0400 (EDT)


Diabolic Crab,

The title and text of this advisory suggest SQL injection, but I don't
see any any clear examples that demonstrate this.

A modified Query parameter to the search function is given, and the
parameter starts with the "'" character - which might *suggest* SQL
injection - but the resulting error message suggests that it's using
the input for some array operations, which could be the fairly common
"bad data type" problem that leads to full path disclosure on PHP
applications.  Indeed there might be other invalid characters that
could trigger the same problem (I don't know; I don't have ArticleLive
available to test).

Could you provide more specific examples or otherwise clarify the
problem?


Thanks,
Steve


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]