PlanetCreator has reported another critical SQL Injection (vulnerability) on Yadanapura : The Gateway to Myanmar Creative Industries http://www.yadanapura.com powered by IndexMyanmar

This vulnerability has been alerted to :- [email protected]

SQL injection is a code injection technique that exploits a security vulnerability occurring in the database layer of an application. The vulnerability is present when user input is either incorrectly filtered for string literal escape characters embedded in SQL statements or user input is not strongly typed and thereby unexpectedly executed.

Applications: ———— PlanetCreator’s_Universal_Advanced_Internet_Security_T00L
System Time: ———— (UTC+08:00) Yangoon, Myanmar , 18/09/2010 08:28:53 PM
Host IP: 198.68.161.4
Database: yadanapura

Some Tables are as follow :

ydn_weekartwork
ydn_spotnew
ydn_ownership
ydn_newsletters
ydn_member
ydn_mb_artwork
ydn_galdirectory
ydn_for_sale
ydn_feature
ydn_exreception
ydn_exhibition
ydn_exartwork
ydn_artworkstyle
ydn_artworkstatus
ydn_artworkmedium
ydn_artworkdetails
ydn_artnews
ydn_artlink
ydn_artisttype
ydn_artiststatement
ydn_artistopinion
ydn_artistmaster
ydn_artistlist
ydn_artistinterview
ydn_artistfeature
ydn_artistcomment
ydn_adm_pass 

We hope that your security staff will look into this issue and fix it as soon as possible.

Explore More

[FUD] Simple command-line binder

First of all, why a command-line binder? Automation. Instead of sitting there binding individual, or even groups of files yourself, you can easily automate the binding process by using a

WikiLeaks supporters step up cyber war

LONDON (AFP)— A group of hackers vowed on Thursday to intensify a “war of data” against Mastercard, Visa and other groups which have cut funding to the WikiLeaks website over

Targets of a Hack Attack

Hacker interests lie in many types of computers on the Internet. Following is a discussion of the types of targets and their appeal to the perpetrators.Corporate Networks Corporate computers are