lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20060921223409.13188.qmail@securityfocus.com> Date: 21 Sep 2006 22:34:09 -0000 From: sn4k3.23@...il.com To: bugtraq@...urityfocus.com Subject: Woltlab Burning Board 2.3.X SQL Injection Vulnerability Use it like this: http://127.0.0.1/wbb2/thread.php?threadid=1&page=-1 Ok, its kinda useless 'cause it's an "ORDER BY", but u can see: - the PHP Version - the MySQL version - the wBB Version (when it has been faked or removed) Greets, 666 - www.sr-crew.de.tt