SQL injection
Status: Inactive
Brought to you by:
willuhn
SQL injection exists in PMtool in parameter 'order'.
It reveals the table name and column name.
http://www.pmtool.org/demo/index.php
Credit: Pratiksha Doshi, Security Anaylst, NII Consulting
Best Regards
Pratiksha Doshi