Bug: Oxygen<=1.x.x SQL injection (WLB-2006040001 Ascii Version)

English Version
WLB2

CVE WLB2

 Topic: Oxygen<=1.x.x SQL injection
 Credit: DaBDouB-MoSiKaR
 Date: 2006.04.01
 CWE: CWE-89 (Show similar)
 CVE: CVE-2006-1572 (Show details)

Use CVE to see details like:
- CVSS2,
- Affected Software,
- References

Risk
Local
Remote
Medium
No
Yes

author: DaBDouB-MoSiKaR [Moroccan Security Team]
site: www.o2php.com
greetz to : [Moroccan Security Team] CiM-TeaM and All Freinds
Solution: intval()
exemple:
http://[target]/post.php?action=newthread&fid=[sql]
inbox:DaBDouB-MoSiKaR[at]moroccan-security[dot]com

[ ASCII VERSION ]

Copyright 2012, cxsecurity.com