BSM Store Dependent Forums UserName Parameter SQL Injection Vulnerability

Attackers can use a browser to exploit this issue.

The following is an example of SQL code that can be injected into the affected parameter:

' union select * from members where member=1


 

Privacy Statement
Copyright 2010, SecurityFocus