Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
ASPjar guestbook (Injection in login page) Feb 10 2005 07:05PM
farhad koosha (farhadkey yahoo com)


Go to /admin/login.asp and type in password field:
' or ''='
Also in some version of ASPjar , Attackers can delete messages .
Go to /admin/delete.asp
...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus