Ref. [DSF-03-2009] – IXXO Cart! Standalone and Joomla Component SQL Injection
Vendor: IXXO Internet Solutions
Status: Patched by vendor
IXXO Cart!
IXXO Cart is an extremely powerful php shopping cart and web site builder application. Designed from a marketing perspective, this ecommerce application is feature-packed, robust, scalable and easy to use. IXXO Cart Plus is the clear choice for [...]
IRC bot scanner coded in PERL and developed by Vrs-hCk. This tool checks for LFI, RFI, SQL Injections and other types of injections on a IRC environment.
It’s also combined with a injector code that uses the usual gzinflate and base64 plus a few extra str_rot13 php function.
By the way, I already saw this in action [...]
This PHP based catalog is vulnerable to SQL Injection on search form.
Injecting a quote mark will break the SQL query and even provide sensitive database information that could help a malicious user to complete and enter a valid SQL injection query.
SQL Injection is currently a type of attack used by many “defacer” groups outhere, specially against military and government websites.
Most of them just try to insert some text modification to their cause but some are trying to get sensitive data, like military information.
Today I bring you a presentation of another scanner, a SQL Injection scanner [...]
Some hits on a couple of my websites with this scanner written in Python. It’s already public so you can get the full version searching on google or something.
Joomla SQL Injection Scanner v 2.1 , searches for common and public SQL Injection holes on a specific website, but there are rumours that there is already [...]
Hackersblog just published an article about SQLi on Telegraph website and how they ignore the problem.
Recent Comments