Home page logo

bugtraq logo Bugtraq mailing list archives

Orbitmatrix PHP Script v1.0
From: luny () youfucktard com
Date: 13 Jul 2006 10:14:15 -0000

Orbitmatrix PHP Script v1.0


Affected files:

Possible SQL injection?:

And by trying a XSS vuln as shown below on page_name we see the query below which is displayed on screen:


And the displayed query:

Query: select code from pages where name=contact

Now we know the tables name is pages and a row is name.

This works on all variable values.

As the above XSS vuln wont work, we can see that using the one below will:


  By Date           By Thread  

Current thread:
  • Orbitmatrix PHP Script v1.0 luny (Jul 13)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]