 |
 |

|
 |
Détail d'une fiche vulnérabilité |
| |
 |
|
68 Classifieds category.php cat Parameter SQL Injection |
|
 |
Fiche créée le 2008-05-17 00:35:31, dernière mise à jour le 2009-10-23 05:58:53
68 Classifieds contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'category.php' script not properly sanitizing user-supplied input to the 'cat' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
http://[target]/class_ads/category.php?cat=s'+union+select+1,2,3,4,5,6,7,8,9,concat_ws(0x3a3a,id,Username,Password)+from+class_users/*
|
| |
| |
| |
| Référances externes : |
| OSVDB 45247 |
| |
| |
| |
| |
|
 |
|