[38781] in bugtraq
Advanced Guestbook 2.3.1
daemon@ATHENA.MIT.EDU (Spy Hat)
Mon May 9 15:11:15 2005
Date: 8 May 2005 06:18:51 -0000
Message-ID: <20050508061851.9970.qmail@www.securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: Spy Hat <spyhat@spyhat.com>
To: bugtraq@securityfocus.com
There is an SQL Injection in Advanced Guestbook 2.3.1
For Example:
http://www.(yourdomain).com/(yourguestbookdirectory)/index.php?entry='
or
http://www.(yourdomain).com/(yourguestbookdirectory)/index.php?entry=%27
Yours,
SpyHat