[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
LDF (Default.asp) Sql Injection Vulnerability
- To: bugtraq@xxxxxxxxxxxxxxxxx
- Subject: LDF (Default.asp) Sql Injection Vulnerability
- From: Arash.Setayeshi@xxxxxxxxx
- Date: 6 Feb 2010 16:49:26 -0000
Product : LDF
vendor : www.ldf.22.cn
Vulnerable Versions : All
Default.asp Page has an issue on validating "Page" parameter , It could be
exploited by attacker & attacker can inject arbitrary Sql Commands
http://www.example.com/[ldf path]/default.asp?page=[SQL COMMAND]