ClickContact Default.ASP Multiple SQL Injection Vulnerabilities

An attacker can exploit these issues via a web client.

The following URIs demonstrate these issues:

http://www.example.com/default.asp?view=alpha&AlphaSort=[SQL Injection]
http://www.example.com//default.asp?In=[SQL Injection]
http://www.example.com/default.asp?view=All&orderby=[SQL Injection]


 

Privacy Statement
Copyright 2010, SecurityFocus