[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
OneOrZero Helpdesk V1.6.4.1 susceptible to SQL injection and XSS
- To: bugtraq@xxxxxxxxxxxxxxxxx
- Subject: OneOrZero Helpdesk V1.6.4.1 susceptible to SQL injection and XSS
- From: vampire_chiristof@xxxxxxxxx
- Date: 15 Aug 2006 10:57:33 -0000
vendor:
http://www.oneorzero.com/
vuln :
http://[host]/supporter/index.php?t=tupd&id=[SQL]
http://[host]/supporter/index.php?t=tupd&id=[XSS]
Author : Vampire
vampire_chiristof@xxxxxxxxx
Homepage : Www.HackerZ.iR
Www.H4ckerZ.Com
Iran HackerZ Security Team