[Full-disclosure] phxEventManager 2.0 beta 5 search.php search_terms SQL Injection Vulnerability

2012-03-01 Thread David Guimaraes
# Exploit Title: phxEventManager 2.0 beta 5 search.php search_terms SQL Injection Vulnerability # Date: 01/03/2012 # Author: skysbsb # Software Link: http://sourceforge.net/projects/phxeventmanager/ # Version: Web Application # Tested on: Apache/*nix # Dork: intext: Powered by phxEventManager #

[Full-disclosure] SQL injection vulnerability in Zabbix = 1.8.1

2010-05-24 Thread David Guimaraes
Product: Zabbix Vendor: Zabbix SIA References: http://www.securityfocus.com/bid/39752 http://secunia.com/advisories/39119 Software Link: http://www.zabbix.com/ Vulnerable Version: = 1.8.1 Vulnerability Type: SQL Injection Status: Fixed in version 1.8.2 Risk level: Medium Author: David skys