OneOrZero Helpdesk V1.6.4.1 susceptible to SQL injection and XSS
Date: 15 Aug 2006 10:57:33 -0000
From: vampire_chiristof@yahoo.com
To: bugtraq@securityfocus.com
Subject: OneOrZero Helpdesk V1.6.4.1 susceptible to SQL injection and XSS
X-Virus-Scanned: antivirus-gw at tyumen.ru
vendor:
http://www.oneorzero.com/
vuln :
http://[host]/supporter/index.php?t=tupd&id=[SQL]
http://[host]/supporter/index.php?t=tupd&id=[XSS]
Author : Vampire
vampire_chiristof@yahoo.com
Homepage : Www.HackerZ.iR
Www.H4ckerZ.Com
Iran HackerZ Security Team