Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Vbulletin 3.7.0 Gold >> Sql injection on faq.php May 20 2008 02:49PM
a jasbi yahoo com
By : Ali Jasbi(Hackerz.ir security & hacking research team)

Vendor : vbulletin.org

version : 3.7.0 Gold

Vulnerability: Sql injection

http://www.domain.com/vBulletin/faq.php?s=&do=search&q=[Sql injection]&match=any&titlesonly=1

test it:

faq.php?s=&do=search&q='&match=any&titlesonly=1

faq.php?s...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus