BugTraq
Back to list
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
Re: Mybb 1.6.8 'announcements.php' Sql Injection Vulnerabilitiy
Jun 26 2012 04:46PM
Gianluca Brindisi (g brindi si)
Isn't $aid already escaped by intval() ?
Gianluca
On Fri, Jun 22, 2012 at 10:13 PM, Yaniv Shaked <yaniv0a (at) gmail (dot) com [email concealed]> wrote:
>
> Look at the code at announcements.php:
>
> $aid = intval($mybb->input['aid']);
>
> [Boring lines?]
>
> [Boring lines?]
>
> $query = $db->query("
> SELECT u.*, u.us...
[ more ]
Privacy Statement
Copyright 2010, SecurityFocus
Gianluca
On Fri, Jun 22, 2012 at 10:13 PM, Yaniv Shaked <yaniv0a (at) gmail (dot) com [email concealed]> wrote:
>
> Look at the code at announcements.php:
>
> $aid = intval($mybb->input['aid']);
>
> [Boring lines?]
>
> [Boring lines?]
>
> $query = $db->query("
> SELECT u.*, u.us...
[ more ]