[prev in list] [next in list] [prev in thread] [next in thread] 

List:       bugtraq
Subject:    Oxygen<=1.x.x SQL injection
From:       dabdoub-mosikar () moroccan-security ! com
Date:       2006-03-30 22:12:06
Message-ID: 20060330221206.20258.qmail () securityfocus ! com
[Download RAW message or body]

author: DaBDouB-MoSiKaR [Moroccan Security Team]
site: www.o2php.com
greetz to : [Moroccan Security Team] CiM-TeaM and All Freinds
Solution: intval()
exemple:
http://[target]/post.php?action=newthread&fid=[sql]
inbox:DaBDouB-MoSiKaR[at]moroccan-security[dot]com 
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic