This is a detailed vulnerability writeup describing a SQL injection flaw in PHPList versions 3.0.6 and 3.0.10. The vulnerability is located in the 'findby' parameter of the user search module and can be exploited via a GET request.
Classification
Writeup 100%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target:PHPList v3.0.6 & v3.0.10
Auth required
Prerequisites:Low-privileged web-application user account