------------------------------------------------------------------------
Freelancer calendar <= 1.01 SQL Injection Vulnerability
------------------------------------------------------------------------
Author: muuratsalo (Revshell.com) www.2cto.com muuratsalo [at] gmail [dot] com
: Http://sourceforge.net/projects/freelancercal/
[0x01] defect Overview:
Freelancer calendar <= 1.0.1 is affected by SQL Injection defects.
Note: a registered account is required to exploit this vulnerability.
Example:
The http://www.bkjia.com/worldcalendar/category_list.php? A = search & value = 1 & SearchFor = muuratsalo & SearchOption = Contains & SearchField = [SQL
Injection]
Http://www.bkjia.com/worldcalendar/Copy_of_calendar_list.php? A = search & value = 1 & SearchFor = muuratsalo & SearchOption = Contains & SearchField = [SQL
Injection]
Http://www.bkjia.com/worldcalendar/customer_statistics_list.php? A = search & value = 1 & SearchFor = muuratsalo & SearchOption = Contains & SearchField = [SQL
Injection]
Http://www.bkjia.com/worldcalendar/customer_list.php? A = search & value = 1 & SearchFor = muuratsalo & SearchOption = Contains & SearchField = [SQL
Injection]
Http://www.bkjia.com/worldcalendar/task_statistics_list.php? A = search & value = 1 & SearchFor = muuratsalo & SearchOption = Contains & SearchField = [SQL
Injection]
Www.2cto.com:
For the above page, filter parameter input