Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: mcRefer SQL injection Feb 11 2007 11:26AM
gmdarkfig gmail com
This is not an SQL Injection. The script don't use any SQL database, please tell me where is the sql request =). However the install.php script can lead to php code execution (works regardless of php.ini settings). Proof of concept:
-----

#!/usr/bin/php
<?php
# This file require the PhpSploit class...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus