Exploit Xpressions Interactive - Multiple SQL Injections

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
22724
Проверка EDB
  1. Пройдено
Автор
PAUL CRAIG
Тип уязвимости
WEBAPPS
Платформа
ASP
CVE
null
Дата публикации
2003-06-04
Код:
source: https://www.securityfocus.com/bid/7804/info

Several software products maintained by Xpressions Interactive are prone to SQL injection attacks.

The vulnerability exists in the login.asp page. Specifically, user-supplied input is not sufficiently sanitized of malicious SQL queries.

An attacker may exploit this vulnerability to insert SQL code into requests and have the SQL code executed by the underlying database server. 

http://examplestore.com/manage/login.asp
User: admin
Pass: ' or '1' = '1
 
Источник
www.exploit-db.com

Похожие темы