OpenBB Multiple SQL Injection Vulnerabilities

No exploit is required.

Examples have been provided:

http://www.example.com/openbb/board.php?FID=[sql]
http://www.example.com/openbb/read.php?TID=[sql]
http://www.example.com/openbb/member.php?action=profile&UID=[sql]


 

Privacy Statement
Copyright 2010, SecurityFocus