lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20060330221206.20258.qmail@securityfocus.com> Date: 30 Mar 2006 22:12:06 -0000 From: dabdoub-mosikar@...occan-security.com To: bugtraq@...urityfocus.com Subject: Oxygen<=1.x.x SQL injection author: DaBDouB-MoSiKaR [Moroccan Security Team] site: www.o2php.com greetz to : [Moroccan Security Team] CiM-TeaM and All Freinds Solution: intval() exemple: http://[target]/post.php?action=newthread&fid=[sql] inbox:DaBDouB-MoSiKaR[at]moroccan-security[dot]com