Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: SQL injection - GestDownV1.00Beta

SQL injection - GestDownV1.00Beta

From: <bebe_at_gmail.com>
Date: 9 Dec 2007 02:49:47 -0000
('binary' encoding is not supported, stored as-is) catdownload.php (line 16)
$sql = ('SELECT * FROM downloads WHERE categorie='.$categorie.'');

download.php (line 6)
mysql_query('SELECT * FROM `downloads` WHERE categorie=' . $_GET['id']);

hitcounter.php (line 15)
$requete = "SELECT lien FROM downloads WHERE id=$id";

download:
http://www.01php.com/fiche-scripts-148.html
Received on Dec 10 2007

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos