The vulnerability allows an attacker to inject sql commands into the 'key' parameter of the 'index.php' page, which can be used to access or modify the contents of the database.
An unauthenticated attacker can write arbitrary files to the web-server root directory by exploiting the lack of input validation in Mako web-server tutorial. This can lead to remote command execution.
The vulnerability allows an attacker to inject sql commands into the 'key' parameter of the 'index.php' page.
The vulnerability allows an attacker to inject sql commands. Proof of Concept: http://localhost/[PATH]/index.php?page=static_pages&key=[SQL]
The vulnerability allows an attacker to inject sql commands. Proof of Concept: http://localhost/[PATH]/index.php?page=static_pages&key=[SQL]
The vulnerability allows an attacker to inject sql commands into the vulnerable parameter 'key' of the 'index.php' page.
The vulnerability allows an attacker to inject sql commands into the vulnerable parameters of the application. Proof of Concept: http://localhost/[PATH]/index.php?page=static_page&key=[SQL], http://localhost/[PATH]/survey.php?page=preview&test=[SQL]
The vulnerability allows an attacker to inject sql commands.... Proof of Concept: http://localhost/[PATH]/index.php?page=static_page&key=[SQL] -EfE'+/*!00009UniOn*/+/*!00009SelEcT*/+0x31,0x32,0x3c68313e494853414e2053454e43414e3c2f68313e,(/*!00009Select*/+export_set(5,@:=0,(/*!00009select*/+count(*)from(information_schema.columns)where@:=export_set(5,export_set(5,@,/*!00009table_name*/,0x3c6c693e,2),/*!00009column_name*/,0xa3a,2)),@,2))--+- Etc..
The vulnerability allows an attacker to inject sql commands into vulnerable parameters in the web application. Proof of Concept examples are provided for post_details.php, view_posts.php, and index.php.
The vulnerability allows an attacker to inject sql commands. An attacker can bypass authentication by using 'or 1=1 or ''=' as the username and any value as the password.