Bugtraq mailing list archives

Re: modules name(Downloads)SQL Injection Exploit


From: Paul Laudanski <zx () castlecops com>
Date: Sun, 7 May 2006 22:42:51 -0400 (EDT)

What application are you talking about?

On 5 May 2006 Mster-X () hotmail com wrote:

********************
By: Mr-X
Email: Mster-X () hotmail com
Subject: modules name(Downloads)SQL Injection 
********************

example:-
/modules.php?/modules.php?name=Downloads&d_op=viewdownload&cid=[SQL]

********************


-- 
Paul Laudanski, Microsoft MVP Windows-Security
Submit phish: www.castlecops.com/pirt
[de] http://de.castlecops.com
[en] http://castlecops.com
[wiki] http://wiki.castlecops.com


Current thread: