ASPBB Multiple SQL Injection Vulnerabilities

No exploit is required.

The following proof of concept URI are available:
http://www.example.com/aspbb/topic.asp?TID=[sql injection]
http://www.example.com/aspbb/topic.asp?COMMAND=GOTOLAST&TID=[sql injection]
http://www.example.com/aspbb/forum.asp?FORUM_ID=[sql injection]
http://www.example.com/aspbb/profile.asp/PROFILE_ID=[sql injection]


 

Privacy Statement
Copyright 2010, SecurityFocus