Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Expinion.net Member Management System ID Parameter SQL Injection Vulnerability

It has been reported that Member Management System may be prone to a SQL injection vulnerability that may allow a remote attacker to inject malicious SQL syntax into database queries. The problem is reported to exist in the 'ID' parameter contained within the 'resend.asp' and 'news_view.asp' scripts.

Member Management System version 2.1 has been reported to be affected by this issue, however, other versions may be vulnerable as well.







 

Privacy Statement
Copyright 2009, SecurityFocus