Bugtraq mailing list archives

ASPjar guestbook (Injection in login page)


From: farhad koosha <farhadkey () yahoo com>
Date: 10 Feb 2005 19:05:10 -0000



Go to /admin/login.asp and type in password field:
' or ''='
Also in some version of ASPjar , Attackers can delete messages .
Go to /admin/delete.asp


Current thread: