This is a writeup describing a SQL injection vulnerability in mieRic addressBook 1.0. The vulnerability occurs in the 'no.pl' file where user input is directly interpolated into an SQL query without proper sanitization.
Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target:mieRic addressBook 1.0
Auth required
Prerequisites:Access to the application with valid credentials