Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Web applications security vulnerabilities (PHP, ASP, CGI, Perl, etc)

  Xss в Movable Type

  Instant Photo Gallery SQL inj. vuln.

  phpAlbum Local file include vuln.

  N-13 News Remote SQL/PHP Shell injection

From:info_(at)_hoder.com <info_(at)_hoder.com>
Date:30.11.2005
Subject:ASP-Rider Default.asp SQL Injection

Vendor : http://www.asp-rider.com
Vulnerable Versions : 1.6

Where is the bug
----------------------
in default.asp :
refsss=split(refererssss, "/",-1,1)
refererdomain=refsss(2)
strsql="Select * From tbl_refererd where domain='" & refererdomain & "'"
objrs.open strsql, objconn,3,3
----------------------

and you can enter sql code to database with this referer CODE --> "http://[SQLINJECTION]"

ASP-Rider splits "http://[SQLINJECTION]"
two sections are :
1)http://
2)[SQLINJECTION]

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru