View Single Post
  #1  
Old 4th November 2018, 23:34
BamBam0077 BamBam0077 is offline
Banned
 
Join Date: Jul 2013
P2P
Posts: 410
Default SQL Injection adminCP
Hey I don't know if any of you guys checked your admincp fully you will see vars inside an query not covered with sqlesc() you might do so by going to your /var/www/html/ grab admincp.php now search for your sql_query and update the vars to be protect with sqlesc() also I know it is not like tbdev so sql query is different and you will need to check tbdev to get sqlesc() it was a quick scan if you know more then please share with me here
Click the image to open in full size.
Reply With Quote