[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <48346813.3020905@corest.com>
Date: Wed, 21 May 2008 15:21:07 -0300
From: Matias Blanco <blue@...est.com>
To: bugtraq@...urityfocus.com
Subject: Re: Vbulletin 3.7.0 Gold >> Sql injection on faq.php
This exploit is valid. We've just exploted it.
VBulletin 3.7.0 Gold.
martin.meredith@...lletin.com wrote:
> This is invalid. the variable q is taken, split into words, and then each word is escaped for usage within the DB.
>
> Once again, this is invalid
>
Powered by blists - more mailing lists