AOH :: Web BBS :: Frequently Exploited :: B06-2154.HTM

phpBB "charts.php" XSS and SQL-Injection

phpBB "charts.php" XSS and SQL-Injection
phpBB "charts.php" XSS and SQL-Injection



// phpBB "charts.php" (hack) XSS and SQL-Injection //=0D
=0D
-----------------------------------------------------------------=0D
=0D
[~] Advisory by: LoK-Crew=0D
=0D
[-] Exploit:=0D
http://www.example.com/charts.php?action=vote&rate=1&id=[XSS]=0D 
http://www.example.com/charts.php?action=vote&rate=1&id=[SQL]=0D 
=0D
[-] Googledork: inurl:"charts.php" "powered by phpbb"=0D
=0D
[+] Visit: www.LoK-Crew.de 

The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2009 AOH
We do not send spam. If you have received spam bearing an artofhacking.com email address, please forward it with full headers to abuse@artofhacking.com.