BugTraq
ClickContact SQL Injection Nov 26 2006 08:40PM
Advisory Aria-Security Net
#Aria-Security Team Advisory
#<www.Aria-security.Com For English >
#<www.Aria-Security.net For Persian >
#-----------------------------------------------------------
#Software: Click Contact
#Method: SQL injection
#
#PoC:
#http://target/default.asp?view=alpha&AlphaSort=[SQL Injection]
#http://target/default.asp?In=[SQL INJECTION]
#http://target/default.asp?view=All&orderby=[SQL Injection]
#
#Contact: Advisory (at) aria-security (dot) net [email concealed]

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus