header-logo
Suggest Exploit
vendor:
PsNews
by:
S.W.T
7,5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: PsNews
Affected Version From: 1.3
Affected Version To: 1.3
Patch Exists: NO
Related CWE: N/A
CPE: a:psnews:psnews:1.3
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Linux & Windows
2010

PsNews Sql Injection Vulnerability

A vulnerability exists in PsNews 1.3 which allows an attacker to inject arbitrary SQL commands via the 'id' parameter in ndetail.php and print.php.

Mitigation:

Input validation should be used to prevent SQL injection attacks.
Source

Exploit-DB raw data:

#########################################################################################
# Exploit Title : PsNews Sql Injection Vulnerability
# Date : 6 - 7 - 2010
# Author : S.W.T
# Vendor : http://www.psnews.sourceforge.net
# Version : 1.3
# Tested on : Linux & Windows
# Home : WwW.SeC-WaR.CoM <http://www.sec-war.com/>
#########################################################################################

                                               -== SQL Injection
Vulenrability ==-

http://www.[site].com/[path]/ndetail.php?id=[SQL1]

http://www.[site].com/[path]/print.php?id=[SQL2]


#########################################################################################

                                                 This Is Security War Team

                                        Penetration Testing & Ethical Hacking

                                                       No More Privates

#########################################################################################