newsfactory Cross Site Scripting & SQL injection
Date: 2 Jun 2006 14:35:54 -0000
From: CrAzY.CrAcKeR@hotmail.com
To: bugtraq@securityfocus.com
Subject: newsfactory Cross Site Scripting & SQL injection
X-Virus-Scanned: antivirus-gw at tyumen.ru
Discovery By: CrAzY CrAcKeR
Site: www.alshmokh.com
I want to thank my friend:-
nono225-mHOn-rageh-LoverHacker-BoNy_m
Breeeeh-Rootshil-LiNuX_rOOt-SauDiVirUS
Example:-
/vorstellung.php?id=[sql]
/vorstellung.php?id=[xss]
Email: CrAzY.CrAcKeR(at)hotmail(dot)com