|
|
|
|
Menu |
|
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
|
User Info |
|
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 59
Members: 0
Total: 59
|
|
|
|
|
|
Full disclosure |
|
|
|
|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
|
from what i remember nessus is not free anymore(application,plugins), you can try openvas
thanks for this tip. OpenVAS looks kinda similiar to Nessus, but free. Gonna compile @ freebsd and try out. |
|
|
|
|
well free with "home feed", kinda retarded and outdated security check (2+ month old).
Professional feed cost ~$1200/year... I was hoping some carder got a subscription |
|
|
|
|
Does anyone have/know if someone publish their proffesional feed plugins?
Does anyone uses nessus at all? |
|
|
|
|
4. Sql Injection in "shop_browse_queries.php"
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Security risk: high
Preconditions: none
Comments:
1. This is blind sql injection
======= ... |
|
|
|
|
On the target.
And yes, information gathered from <?php phpinfo() ?>
Btw, about #1, if this should be used like?
URL/index.php?page=shop.pdf_output&option=com_virtuemart&showp ... |
|
|
|
|
I've tested first 2 exploits on my Virtuemart 1.1.2 shops (3 sites).
None of the works.
as for #1 with remote exectuion - there is no file "/usr/bin/htmldoc", so it's okey
#2 - I have all req ... |
|
|
Page 1 of 1 |
All times are GMT |
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|