Home arrow Vendor Advisories arrow Open Source Vul DB arrow Dragon Internet Events Listing admin_login.asp Multiple Field SQL Injection
Wednesday, 03 December 2008
 
spacer.png, 0 kB
spacer.png, 0 kB
spacer.png, 0 kB
Dragon Internet Events Listing admin_login.asp Multiple Field SQL Injection
Thursday, 16 November 2006
Events Listing contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'admin_login.asp' script not properly sanitizing user-supplied input to the 'username' and 'password' variables. This may allow an attacker to inject or manipulate SQL queries in the backend database.
Read more...
 
spacer.png, 0 kB
     

© 2008 Intellect Information Technology Pty Ltd, Melbourne, Australia.

This page was loaded in 0.052 seconds.