9 lines
No EOL
469 B
Text
9 lines
No EOL
469 B
Text
source: https://www.securityfocus.com/bid/18790/info
|
|
|
|
VirtuaStore is prone to an SQL-injection vulnerability because it fails to properly sanitize user-supplied input before using it in SQL queries.
|
|
|
|
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
|
|
|
|
The following entered in the password field is sufficient to exploit this issue:
|
|
|
|
123456 / ' or 1=1 |