Found by E.Minaev (underwater (at) itdefence (dot) ru [email concealed])
ITDefence.ru
1) SQL Injection in login function. With help of this injection is possible to make per-symbol brute of tables names of blog's database (magic_quotes_gpc should be tured off).
ITDefence.ru
1) SQL Injection in login function. With help of this injection is possible to make per-symbol brute of tables names of blog's database (magic_quotes_gpc should be tured off).
------------------------------------------
"$sql = "select * fro...
[ more ]