sa-2003-04-myclassified.pdf...

- AV AC AU C I A
发布: 2003-11-04
修订: 2025-04-13

MyClassifieds SQL Versions below 2.13 are vulnerable to a SQL injection attack. The problem is due to improper sanitization of user input for the email variable. A remote attacker could insert arbitrary SQL code in the email variable. The passwords of the users can be written into a file and made world readable.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息