Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

GA's Forum Light Archive.ASP SQL Injection Vulnerability


An exploit is not required.

The following proof-of-concept URI are available:

http://www.example.com/forum/archive.asp?Forum=Test+Forum%5F1%2D13%2D2004%5F11%2D28%2D2004&pages='
http://www.example.com/forum/archive.asp?Forum='%20or%20'='%5F1%2D13%2D2004%5F11%2D28%2D2004&pages=4







 

Privacy Statement
Copyright 2009, SecurityFocus