[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
PhxContacts <= 0.93.1 beta Multiple SQL injection & xss
- To: bugtraq@xxxxxxxxxxxxxxxxx
- Subject: PhxContacts <= 0.93.1 beta Multiple SQL injection & xss
- From: dabdoub-mosikar@xxxxxxxxxxxxxxxxxxxxx
- Date: 28 Mar 2006 23:01:57 -0000
[+]PhxContacts
[+]website of software:http://www.phoetux.net/
[+]founded by Morocco Security Team
[+]special 10x to:all friends ww.lezr.com & www.cim-team.org
[+]xss
[+]http://[target]/login.php?m=[xss]
[+]SQL
[+]http://[target]/carnet.php?view_cat=&all_lines=true&motclef=[sql]
[+]http://[target]carnet.php?view_cat=2&nbr_line_view=[sql]
[+]http://[target]/contact_view.php?id_contact=[sql]
[+]have nice day