Re: Vbulletin 3.6.5 Sql Injection ! [misc.php]

看板Bugtraq作者時間19年前 (2007/04/15 00:26), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串2/2 (看更多)
There is no SQL injection being performed on that page, the proof of concept script simple grabs any 32 character string from the page, the one in question happens to be a logout hash. The logout hash is used to mitigate a CSRF.
文章代碼(AID): #168G2m00 (Bugtraq)
文章代碼(AID): #168G2m00 (Bugtraq)