‘Andy’s PHP Knowledgebase’ SQL Injection Vulnerability (CVE-2011-1546)

0
49

Posted by Mark Stanislav on Mar 30

‘Andy’s PHP Knowledgebase’ SQL Injection Vulnerability (CVE-2011-1546)
Mark Stanislav – mark.stanislav () gmail com

I. DESCRIPTION
—————————————
A vulnerability exists in a_viewusers.php allowing for SQL injection of the ‘s’ query parameter.

II. TESTED VERSION
—————————————
0.95.2

III. PoC EXPLOIT
—————————————…

Source: ‘Andy’s PHP Knowledgebase’ SQL Injection Vulnerability (CVE-2011-1546)