info
discussion
exploit
solution
references
PHPMyFAQ Password.PHP SQL Injection Vulnerabililty
No exploit is required.
An example has been provided:
switch to /admin directory, click on "forgotten password" feature
user: ' or isnull(1/0) /*
mail: [your_email]
Privacy Statement
Copyright 2010, SecurityFocus