OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Aceboard forum, SQL injection

karmaguedonhotmail.com
Date: Fri Aug 03 2007 - 07:13:39 CDT


Aceboard is prone to a sql injection vulnerability because it fails to properly sanitize user-supplied input into Recherche.php form.

An attacker can exploit this issue to modify initial query and reveal information from mysql databse.

see u, karmaguedon