Title: url shortener script 1.0 SQL injection Vulnerabilities
Author: M. Jock3R www.2cto.com
Development official: http://djpate.com/
: Http://www.phpkode.com/scripts/item/url-shortener-script/
Test Platform: windows XP Sp2 FR
========================================================== ========================================================== ===
Defect file: show. php
Defect code analysis:
If ($ _ GET ['id']) {
Require ("mysql. php ");
$ Id = addslashes ($ _ GET ['id']);
$ GetUrl = mysql_query ("select url from urls where id = $ id ");
Example:
Http://www.bkjia.com/url-shortener-script/show. php? Id = [Inj 3ct]
========================================================== ========================================================== ===
Fixed: filter input on this page
Greets:
Adelsbm/attiadona/Wjunction forum
---------------------------------
I Love you Mindy
---------------------------------
Email: madrido.jocker@gmail.com
Thanks to all algerians HACK3RS