[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Advanced Guestbook 2.3.1
- To: bugtraq@xxxxxxxxxxxxxxxxx
- Subject: Advanced Guestbook 2.3.1
- From: Spy Hat <spyhat@xxxxxxxxxx>
- Date: 8 May 2005 06:18:51 -0000
There is an SQL Injection in Advanced Guestbook 2.3.1
For Example:
http://www.(yourdomain).com/(yourguestbookdirectory)/index.php?entry='
or
http://www.(yourdomain).com/(yourguestbookdirectory)/index.php?entry=%27
Yours,
SpyHat