Sql Injection Demonstrated 29.06.08
Hi,
I have OSC CRE store and just read about a security issue with the links.php and links_submit.php files
I know that there is already a patch that fix this, but I am interested to see if my store was ever vulnerable. I already patched my own store, but I installed the original CRE version that I had, on a demo server.
What I want is simple - I just want to see an explained demonstration of this SQL injection exploit on my demo store and an explanation of how to manually fix the files myself (without patching using the official CRE update).
The demo store is here:
http://64.131.66.36/cre/
Attached is a zipped archive of the original files.
Thanks



