The provided text describes an SQL injection vulnerability in ODFaq, where the 'cat' parameter in faq.php is not properly sanitized. The example demonstrates how an attacker could inject malicious SQL queries via the URL.
Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target:ODFaq (version unspecified)
No auth needed
Prerequisites:Access to the vulnerable ODFaq application