source: http://www.securityfocus.com/bid/24414/info Just For Fun Network Management and Monitoring System (JFFNMS) is prone to multiple remote vulnerabilities, including a cross-site scripting issue, an SQL-injection issue, and multiple information-disclosure issues. An attacker can exploit these issues by manipulating the SQL query logic to carry out unauthorized actions on the underlying database, access sensitive information, and obtain cookie-based authentication credentials. These issues affect versions prior to JFFNMS 0.8.4-pre3. http://www.example.com/auth.php?user='%20union%20select%202,'admin','$1$RxS1ROtX$IzA1S3fcCfyVfA9rwKBMi.','Administrator'/*&pass=
Related Exploits
Trying to match CVEs (1): CVE-2007-3190Trying to match OSVDBs (1): 37166
Other Possible E-DB Search Terms: JFFNms 0.8.3, JFFNms
Date | D | V | Title | Author |
---|---|---|---|---|
2007-06-11 |
![]() |
JFFNms 0.8.3 - 'admin/adm/test.php' PHP Information Disclosure | Tim Brown | |
2007-06-11 |
![]() |
JFFNms 0.8.3 - 'admin/setup.php' Direct Request Authentication Bypass | Tim Brown | |
2007-06-11 |
![]() |
JFFNms 0.8.3 - 'auth.php?user' Cross-Site Scripting | Tim Brown |