exploit-db-mirror/exploits/php/webapps/21527.txt
Offensive Security b4c96a5864 DB: 2021-09-03
28807 changes to exploits/shellcodes
2021-09-03 20:19:21 +00:00

7 lines
No EOL
419 B
Text

source: https://www.securityfocus.com/bid/4971/info
It is reported that MyHelpDesk (version 20020509 and earlier) are vulnerable to SQL injection attacks.
Data supplied by the remote user, via CGI parameters, is used directly as part of SQL statements. As input sanitization is not properly performed, it is possible to modify the logic of a SQL query.
http://[TARGET]/supporter/index.php?t=detailticket&id=root%20me