Guest User

www.nytimes.com SQLi vulnerabilities

a guest
Jun 3rd, 2012
281
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 10.70 KB | None | 0 0
  1. www.nytimes.com SQLi vulnerabilities
  2.  
  3. <ReferURL>http://www.nytimes.com/pages/fashion/index.html^top=http://topics.nytimes.com/top/reference/timestopics/people/a/azzedine_alaia/index.html</ReferURL>
  4. <Parameter>top=http://topics.nytimes.com/top/reference/timestopics/people/a/azzedine_alaia/index.html</Parameter>
  5. <Type>String</Type>
  6. <KWordActionURL>Looking</KWordActionURL>
  7. <Vulnerability>POST SQL INJECTION</Vulnerability>
  8. </VulRow>
  9. - <VulRow>
  10. <ReferURL>http://www.nytimes.com/adx/bin/adx_click.html?pos=TopLeft&sn2=ab8a95f5/87622a3f&sn1=3629d149/66b1e765&camp=Marc_Jacobs_2012_1793606-nyt8&ad=MJ_BAL_HARBOUR_LEFT_529&goto=http%3A%2F%2Fwww%2Emarcjacobs%2Ecom%2Fmarc%2Djacobs%2Feyewear%2Fmmj408%2Ds%2Fmarc%2Djacobs%2Doversized%2Dsunglasses%3Futm%5Fsource%3Dnytimes%26utm%5Fmedium%3Dlefttile%26utm%5Fcampaign%3Dmjwoversizedsunglasses&type=goto&opzn&page=homepage.nytimes.com/index.html</ReferURL>
  11. <Parameter>page=homepage.nytimes.com/index.html</Parameter>
  12. <Type>String</Type>
  13. <KWordActionURL>Green</KWordActionURL>
  14. <Vulnerability>URL SQL INJECTION</Vulnerability>
  15. </VulRow>
  16. - <VulRow>
  17. <ReferURL>http://www.nytimes.com/adx/bin/adx_click.html?pos=TopLeft&sn2=ab8a95f5/87622a3f&sn1=3629d149/66b1e765&camp=Marc_Jacobs_2012_1793606-nyt8&ad=MJ_BAL_HARBOUR_LEFT_529&goto=http%3A%2F%2Fwww%2Emarcjacobs%2Ecom%2Fmarc%2Djacobs%2Feyewear%2Fmmj408%2Ds%2Fmarc%2Djacobs%2Doversized%2Dsunglasses%3Futm%5Fsource%3Dnytimes%26utm%5Fmedium%3Dlefttile%26utm%5Fcampaign%3Dmjwoversizedsunglasses&type=goto&opzn^page=homepage.nytimes.com/index.html</ReferURL>
  18. <Parameter>page=homepage.nytimes.com/index.html</Parameter>
  19. <Type>String</Type>
  20. <KWordActionURL>GRAND</KWordActionURL>
  21. <Vulnerability>COOKIE SQL INJECTION</Vulnerability>
  22. </VulRow>
  23. - <VulRow>
  24. <ReferURL>http://www.nytimes.com/adx/bin/adx_click.html?sn2=ab8a95f5/87622a3f&sn1=3629d149/66b1e765&camp=Marc_Jacobs_2012_1793606-nyt8&ad=MJ_BAL_HARBOUR_LEFT_529&goto=http%3A%2F%2Fwww%2Emarcjacobs%2Ecom%2Fmarc%2Djacobs%2Feyewear%2Fmmj408%2Ds%2Fmarc%2Djacobs%2Doversized%2Dsunglasses%3Futm%5Fsource%3Dnytimes%26utm%5Fmedium%3Dlefttile%26utm%5Fcampaign%3Dmjwoversizedsunglasses&type=goto&opzn&page=homepage.nytimes.com/index.html&pos=TopLeft</ReferURL>
  25. <Parameter>pos=TopLeft</Parameter>
  26. <Type>String</Type>
  27. <KWordActionURL>swapImgRestore</KWordActionURL>
  28. <Vulnerability>URL SQL INJECTION</Vulnerability>
  29. </VulRow>
  30. - <VulRow>
  31. <ReferURL>http://www.nytimes.com/adx/bin/adx_click.html?sn2=ab8a95f5/87622a3f&sn1=3629d149/66b1e765&camp=Marc_Jacobs_2012_1793606-nyt8&ad=MJ_BAL_HARBOUR_LEFT_529&goto=http%3A%2F%2Fwww%2Emarcjacobs%2Ecom%2Fmarc%2Djacobs%2Feyewear%2Fmmj408%2Ds%2Fmarc%2Djacobs%2Doversized%2Dsunglasses%3Futm%5Fsource%3Dnytimes%26utm%5Fmedium%3Dlefttile%26utm%5Fcampaign%3Dmjwoversizedsunglasses&type=goto&opzn&page=homepage.nytimes.com/index.html^pos=TopLeft</ReferURL>
  32. <Parameter>pos=TopLeft</Parameter>
  33. <Type>String</Type>
  34. <KWordActionURL>swapImgRestore</KWordActionURL>
  35. <Vulnerability>COOKIE SQL INJECTION</Vulnerability>
  36. </VulRow>
  37. - <VulRow>
  38. <ReferURL>http://www.nytimes.com/adx/bin/adx_click.html?type=goto&opzn&page=homepage.nytimes.com/index.html&pos=TopRight&sn2=361d9a2f/d5c54928&sn1=f1bbbfb9/f17f2a97&camp=Marc_Jacobs_2012_1793606-nyt8&ad=MJ_BAL_HARBOUR_RIGHT_529^goto=http%3A%2F%2Fwww%2Emarcjacobs%2Ecom%2Fstore%2Flist%3Fcc%3Dus%26city%3Dbalharbour%26utm%5Fsource%3Dnytimes%26utm%5Fmedium%3Drighttile%26utm%5Fcampaign%3Dmjbalharbourstore</ReferURL>
  39. <Parameter>goto=http%3A%2F%2Fwww%2Emarcjacobs%2Ecom%2Fstore%2Flist%3Fcc%3Dus%26city%3Dbalharbour%26utm%5Fsource%3Dnytimes%26utm%5Fmedium%3Drighttile%26utm%5Fcampaign%3Dmjbalharbourstore</Parameter>
  40. <Type>String</Type>
  41. <KWordActionURL>movieWidth</KWordActionURL>
  42. <Vulnerability>COOKIE SQL INJECTION</Vulnerability>
  43. </VulRow>
  44. - <VulRow>
  45. <ReferURL>http://www.nytimes.com/adx/bin/adx_click.html?sn1=f1bbbfb9/f17f2a97&camp=Marc_Jacobs_2012_1793606-nyt8&ad=MJ_BAL_HARBOUR_RIGHT_529&goto=http%3A%2F%2Fwww%2Emarcjacobs%2Ecom%2Fstore%2Flist%3Fcc%3Dus%26city%3Dbalharbour%26utm%5Fsource%3Dnytimes%26utm%5Fmedium%3Drighttile%26utm%5Fcampaign%3Dmjbalharbourstore&type=goto&opzn&page=homepage.nytimes.com/index.html&pos=TopRight&sn2=361d9a2f/d5c54928</ReferURL>
  46. <Parameter>sn2=361d9a2f/d5c54928</Parameter>
  47. <Type>String</Type>
  48. <KWordActionURL>Green</KWordActionURL>
  49. <Vulnerability>URL SQL INJECTION</Vulnerability>
  50. </VulRow>
  51. - <VulRow>
  52. <ReferURL>http://www.nytimes.com/adx/bin/adx_click.html?sn1=f1bbbfb9/f17f2a97&camp=Marc_Jacobs_2012_1793606-nyt8&ad=MJ_BAL_HARBOUR_RIGHT_529&goto=http%3A%2F%2Fwww%2Emarcjacobs%2Ecom%2Fstore%2Flist%3Fcc%3Dus%26city%3Dbalharbour%26utm%5Fsource%3Dnytimes%26utm%5Fmedium%3Drighttile%26utm%5Fcampaign%3Dmjbalharbourstore&type=goto&opzn&page=homepage.nytimes.com/index.html&pos=TopRight^sn2=361d9a2f/d5c54928</ReferURL>
  53. <Parameter>sn2=361d9a2f/d5c54928</Parameter>
  54. <Type>String</Type>
  55. <KWordActionURL>Street</KWordActionURL>
  56. <Vulnerability>COOKIE SQL INJECTION</Vulnerability>
  57. </VulRow>
  58. - <VulRow>
  59. <ReferURL>http://www.nytimes.com/adx/bin/adx_click.html?ad=MJ_BAL_HARBOUR_RIGHT_529&goto=http%3A%2F%2Fwww%2Emarcjacobs%2Ecom%2Fstore%2Flist%3Fcc%3Dus%26city%3Dbalharbour%26utm%5Fsource%3Dnytimes%26utm%5Fmedium%3Drighttile%26utm%5Fcampaign%3Dmjbalharbourstore&type=goto&opzn&page=homepage.nytimes.com/index.html&pos=TopRight&sn2=361d9a2f/d5c54928&sn1=f1bbbfb9/f17f2a97&camp=Marc_Jacobs_2012_1793606-nyt8</ReferURL>
  60. <Parameter>camp=Marc_Jacobs_2012_1793606-nyt8</Parameter>
  61. <Type>String</Type>
  62. <KWordActionURL>Guard’s</KWordActionURL>
  63. <Vulnerability>URL SQL INJECTION</Vulnerability>
  64. </VulRow>
  65. - <VulRow>
  66. <ReferURL>http://www.nytimes.com/adx/bin/adx_click.html?ad=MJ_BAL_HARBOUR_RIGHT_529&goto=http%3A%2F%2Fwww%2Emarcjacobs%2Ecom%2Fstore%2Flist%3Fcc%3Dus%26city%3Dbalharbour%26utm%5Fsource%3Dnytimes%26utm%5Fmedium%3Drighttile%26utm%5Fcampaign%3Dmjbalharbourstore&type=goto&opzn&page=homepage.nytimes.com/index.html&pos=TopRight&sn2=361d9a2f/d5c54928&sn1=f1bbbfb9/f17f2a97^camp=Marc_Jacobs_2012_1793606-nyt8</ReferURL>
  67. <Parameter>camp=Marc_Jacobs_2012_1793606-nyt8</Parameter>
  68. <Type>String</Type>
  69. <KWordActionURL>movieWidth</KWordActionURL>
  70. <Vulnerability>COOKIE SQL INJECTION</Vulnerability>
  71. </VulRow>
  72. - <VulRow>
  73. <ReferURL>http://www.nytimes.com/pages/style/index.html^top=http://topics.nytimes.com/top/reference/timestopics/people/a/azzedine_alaia/index.html</ReferURL>
  74. <Parameter>top=http://topics.nytimes.com/top/reference/timestopics/people/a/azzedine_alaia/index.html</Parameter>
  75. <Type>String</Type>
  76. <KWordActionURL>Election</KWordActionURL>
  77. <Vulnerability>POST SQL INJECTION</Vulnerability>
  78. </VulRow>
  79. - <VulRow>
  80. <ReferURL>http://www.nytimes.com/adx/bin/adx_click.html?opzn&page=homepage.nytimes.com/index.html&pos=HPTopNav&sn2=2b74eb92/5dc5ec0&sn1=ee808ec3/2b6b0219&camp=nyt2012-digi-pencil-try_a_times-blue-winner_3F696&ad=digitalsubs-try_a_times_blue-winner-pencil-3F696&goto=http%3A%2F%2Fwww%2Enytimes%2Ecom%2Fsubscriptions%2FMultiproduct%2Flp5558%2Ehtml%3Fadxc%3D186963%26adxa%3D301138%26page%3Dhomepage.nytimes.com/index.html%26pos%3DHPTopNav%26campaignId%3D3F696&type=goto</ReferURL>
  81. <Parameter>type=goto</Parameter>
  82. <Type>String</Type>
  83. <KWordActionURL>Green</KWordActionURL>
  84. <Vulnerability>URL SQL INJECTION</Vulnerability>
  85. </VulRow>
  86. - <VulRow>
  87. <ReferURL>http://www.nytimes.com/adx/bin/adx_click.html?opzn&page=homepage.nytimes.com/index.html&pos=HPTopNav&sn2=2b74eb92/5dc5ec0&sn1=ee808ec3/2b6b0219&camp=nyt2012-digi-pencil-try_a_times-blue-winner_3F696&ad=digitalsubs-try_a_times_blue-winner-pencil-3F696&goto=http%3A%2F%2Fwww%2Enytimes%2Ecom%2Fsubscriptions%2FMultiproduct%2Flp5558%2Ehtml%3Fadxc%3D186963%26adxa%3D301138%26page%3Dhomepage.nytimes.com/index.html%26pos%3DHPTopNav%26campaignId%3D3F696^type=goto</ReferURL>
  88. <Parameter>type=goto</Parameter>
  89. <Type>String</Type>
  90. <KWordActionURL>swapImgRestore</KWordActionURL>
  91. <Vulnerability>COOKIE SQL INJECTION</Vulnerability>
  92. </VulRow>
  93. - <VulRow>
  94. <ReferURL>http://www.nytimes.com/adx/bin/adx_click.html?camp=nyt2012-digi-pencil-try_a_times-blue-winner_3F696&ad=digitalsubs-try_a_times_blue-winner-pencil-3F696&goto=http%3A%2F%2Fwww%2Enytimes%2Ecom%2Fsubscriptions%2FMultiproduct%2Flp5558%2Ehtml%3Fadxc%3D186963%26adxa%3D301138%26page%3Dhomepage.nytimes.com/index.html%26pos%3DHPTopNav%26campaignId%3D3F696&type=goto&opzn&page=homepage.nytimes.com/index.html&pos=HPTopNav&sn2=2b74eb92/5dc5ec0&sn1=ee808ec3/2b6b0219</ReferURL>
  95. <Parameter>sn1=ee808ec3/2b6b0219</Parameter>
  96. <Type>String</Type>
  97. <KWordActionURL>Condos</KWordActionURL>
  98. <Vulnerability>URL SQL INJECTION</Vulnerability>
  99. </VulRow>
  100. - <VulRow>
  101. <ReferURL>http://www.nytimes.com/adx/bin/adx_click.html?camp=nyt2012-digi-pencil-try_a_times-blue-winner_3F696&ad=digitalsubs-try_a_times_blue-winner-pencil-3F696&goto=http%3A%2F%2Fwww%2Enytimes%2Ecom%2Fsubscriptions%2FMultiproduct%2Flp5558%2Ehtml%3Fadxc%3D186963%26adxa%3D301138%26page%3Dhomepage.nytimes.com/index.html%26pos%3DHPTopNav%26campaignId%3D3F696&type=goto&opzn&page=homepage.nytimes.com/index.html&pos=HPTopNav&sn2=2b74eb92/5dc5ec0^sn1=ee808ec3/2b6b0219</ReferURL>
  102. <Parameter>sn1=ee808ec3/2b6b0219</Parameter>
  103. <Type>String</Type>
  104. <KWordActionURL>Condominiums</KWordActionURL>
  105. <Vulnerability>COOKIE SQL INJECTION</Vulnerability>
  106. </VulRow>
  107. - <VulRow>
  108. <ReferURL>http://www.nytimes.com/adx/bin/adx_click.html?goto=http%3A%2F%2Fwww%2Enytimes%2Ecom%2Fsubscriptions%2FMultiproduct%2Flp5558%2Ehtml%3Fadxc%3D186963%26adxa%3D301138%26page%3Dhomepage.nytimes.com/index.html%26pos%3DHPTopNav%26campaignId%3D3F696&type=goto&opzn&page=homepage.nytimes.com/index.html&pos=HPTopNav&sn2=2b74eb92/5dc5ec0&sn1=ee808ec3/2b6b0219&camp=nyt2012-digi-pencil-try_a_times-blue-winner_3F696&ad=digitalsubs-try_a_times_blue-winner-pencil-3F696</ReferURL>
  109. <Parameter>ad=digitalsubs-try_a_times_blue-winner-pencil-3F696</Parameter>
  110. <Type>String</Type>
  111. <KWordActionURL>Guard’s</KWordActionURL>
  112. <Vulnerability>URL SQL INJECTION</Vulnerability>
  113. </VulRow>
  114. - <VulRow>
  115. <ReferURL>http://www.nytimes.com/adx/bin/adx_click.html?goto=http%3A%2F%2Fwww%2Enytimes%2Ecom%2Fsubscriptions%2FMultiproduct%2Flp5558%2Ehtml%3Fadxc%3D186963%26adxa%3D301138%26page%3Dhomepage.nytimes.com/index.html%26pos%3DHPTopNav%26campaignId%3D3F696&type=goto&opzn&page=homepage.nytimes.com/index.html&pos=HPTopNav&sn2=2b74eb92/5dc5ec0&sn1=ee808ec3/2b6b0219&camp=nyt2012-digi-pencil-try_a_times-blue-winner_3F696^ad=digitalsubs-try_a_times_blue-winner-pencil-3F696</ReferURL>
  116. <Parameter>ad=digitalsubs-try_a_times_blue-winner-pencil-3F696</Parameter>
  117. <Type>String</Type>
  118. <KWordActionURL>GRAND</KWordActionURL>
  119. <Vulnerability>COOKIE SQL INJECTION</Vulnerability>
  120.  
  121. ======================
  122. Dimension Blood Money
  123. ======================
Advertisement
Add Comment
Please, Sign In to add comment