Bugtraq mailing list archives

Woltlab Burning Board 2.3.X SQL Injection Vulnerability


From: sn4k3.23 () gmail com
Date: 21 Sep 2006 22:34:09 -0000

Use it like this:

http://127.0.0.1/wbb2/thread.php?threadid=1&page=-1

Ok, its kinda useless 'cause it's an "ORDER BY", but u can see:

- the PHP Version
- the MySQL version
- the wBB Version (when it has been faked or removed)

Greets,

666 - www.sr-crew.de.tt


Current thread: