// archives

sql injection

This tag is associated with 6 posts

IXXO Cart! Standalone and Joomla Component SQL Injection

Ref. [DSF-03-2009] – IXXO Cart! Standalone and Joomla Component SQL Injection
Vendor: IXXO Internet Solutions
Status: Patched by vendor
IXXO Cart!
IXXO Cart is an extremely powerful php shopping cart and web site builder application. Designed from a marketing perspective, this ecommerce application is feature-packed, robust, scalable and easy to use. IXXO Cart Plus is the clear choice for [...]

VopCrew Multi Scanner v5.0

IRC bot scanner coded in PERL and developed by Vrs-hCk. This tool checks for LFI, RFI, SQL Injections and other types of injections on a IRC environment.
It’s also combined with a injector code that uses the usual gzinflate and base64 plus a few extra str_rot13 php function.
By the way, I already saw this in action [...]

Zoki Catalog SQL Injection

This PHP based catalog is vulnerable to SQL Injection on search form.
Injecting a quote mark will break the SQL query and even provide sensitive database information that could help a malicious user to complete and enter a valid SQL injection query.

Enigma SQL Inject0r

SQL Injection is currently a type of attack used by many “defacer” groups outhere, specially against military and government websites.
Most of them just try to insert some text modification to their cause but some are trying to get sensitive data, like military information.
Today I bring you a presentation of another scanner, a SQL Injection scanner [...]

Joomla SQL Injection Scanner

Some hits on a couple of my websites with this scanner written in Python. It’s already public so you can get the full version searching on google or something.
Joomla SQL Injection Scanner v 2.1 , searches for common and public SQL Injection holes on a specific website, but there are rumours that there is already [...]

Telegraph newspaper security problem

Hackersblog just published an article about SQLi on Telegraph website and how they ignore the problem.