Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:14979
HistoryNov 09, 2006 - 12:00 a.m.

Y.A.N.S sql injection

2006-11-0900:00:00
vulners.com
9

Product: YANS (yet another news system)
Link: http://sourceforge.net/projects/yans/

vuln code:
$resultado = mysql_query("SELECT * FROM users WHERE username='$username' AND password='$password'") or die (mysql_error());

simple sql injection
' or '1=1
' or '1=1

-navairum