Arsenal.com Sql injection vulnerability+Arsenal club Users credentials ('passwords and emails')

i have found a Blind Sql injection in the arsenal club website ,so i reported it to them,they didnt respond so why would i care ,i can take over the web site by now but i will just leak the users information ,so may be now they will notice some thing .

SQLI FOUND IN :http://cn.arsenal.com/newsdetail.php?id=%Inject_Here%494
if you want to see the users emails and passwords hit this LINK
Share on Google Plus

About Unknown

This is a short description in the author block about the author. You edit it by entering text in the "Biographical Info" field in the user admin panel.

0 commentaires:

Enregistrer un commentaire