[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Aria-Security Team] FipsSHOP SQL Injection
- To: bugtraq@xxxxxxxxxxxxxxxxx
- Subject: [Aria-Security Team] FipsSHOP SQL Injection
- From: Advisory@xxxxxxxxxxxxxxxxx
- Date: 26 Nov 2006 03:14:30 -0000
#Aria-Security Team Advisory
#<www.Aria-security.Com For English >
#<www.Aria-Security.net For Persian >
#-----------------------------------------------------------
#Software: FipsSHOP
#Vendor: http://fipsasp.com/
#Method: SQL Injection
#
#PoC:
#http://target/path/index.asp?cat=[SQL INJECTION]
#http://target/path/index.asp?page=detail&did=[SQL INJECTION]
#
#
#Contact: Advisory@xxxxxxxxxxxxxxxxx
fisasp.com doesn't exist as my whois cl