|
»Forumlar »SE ? SQL Injection
»Page.edit, text injection
https://seditio.com.tr/eski1/forums.php?m=posts&q=359 |
| Author: Kaan, Posted: 2010-02-20 20:39 GMT. |
|
Page.edit, possible unauthorized text injection Seditio 126 ve Alt S?r?mlerini Kullan?yorsan?z A?ag?daki g?ncellemeyi Yapman?z kesinlikle ?nerilir.. Page.edit.inc.php yi a??n alttakini bulun Kod: if ($a=="update") { Alt?na Ekleyin. Kod: sed_check_xg(); Alttakini bulun. Kod: "PAGEEDIT_FORM_SEND" => "page.php?m=edit&a=update&id=".$pag['page_id']."&r=".$r, Alttaki ile de?i?tirin.. Kod: "PAGEEDIT_FORM_SEND" => "page.php?m=edit&a=update&id=".$pag['page_id']."&r=".$r."&".sed_xg(), Details : It may be possible to craft a POST html to edit the content of a page (page.php), impersonating an administrator. Items affected : system/core/page/page.edit.inc.php |
| Author: Azerbaycan, Posted: 2010-02-20 21:25 GMT. |
|
Details : It may be possible to craft a POST html to edit the content of a page (page.php), impersonating an administrator. Items affected : system/core/page/page.edit.inc.php anlamadim,,hangi acigi fixlemisler bolece? |
| Author: Kaan, Posted: 2010-02-20 21:35 GMT. |
| Anlamad?ysan yapma Orda Yaz?yor.. POST html |
| Author: Azerbaycan, Posted: 2010-02-20 21:47 GMT. This post was edited by Azerbaycan (2010-02-20 21:48 GMT, 6032 Gün ago) |
|
yapdim,,anlamadigim ondanki orda ingilisce yaziyor son mesaj 1 dakika English to Turkish translation Detaylar: Bu bir POST html zanaat m?mk?n olabilir, bir y?netici taklit bir sayfa (page.php) i?eri?ini d?zenlemek i?in. translate.google.com dan tercumede bu |
| Powered by Seditio | Print version |