BugTraq
Re: SQL injection in Invision Power Board v2.1.5 Mar 07 2006 10:07AM
mattmecham gmail com
I've tested this and cannot get SQL to execute. The "s" parameter is run past PHP's intval() which knocks off anything that's not a number.

Can you explain how you got this to work?

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus