[Full-disclosure] SQL Injection - Vulnerable Brazilian Website ( AJAX / Web 2.0 )

2006-12-18 Thread Fabio Neves Sarmento [ Gmail ]
Hello folks!! This is the website. ( SQL Injection vulnerability ) Website deloped using web 2.0 concept, very very same as Google tools http://www.misgood.com USER: ' or 1=1 -- PASS: ' or 1=1 -- get logged! now you will see the first ID in the system. Have fun. - Quik ___

[Full-disclosure] Orkut Vulnerability

2007-02-06 Thread Fabio Neves Sarmento [ Gmail ]
Anyone knows if orkut have a news XSS or SQL Injections vulnerability's? ( always have a new xss ) -- + Cordialmente, + Fábio N Sarmento + Analista de Sistemas PL + Vox Line Contact Center + http://www.voxline.com.br + fabior2 [at] gmail.com + 55 11 9978 2646 __