Home arrow Vendor Advisories arrow Open Source Vul DB arrow Dragon Internet Events Listing venue_detail.asp VenueID Variable SQL Injection
Wednesday, 03 December 2008
 
spacer.png, 0 kB
spacer.png, 0 kB
spacer.png, 0 kB
Dragon Internet Events Listing venue_detail.asp VenueID Variable SQL Injection
Thursday, 16 November 2006
Events Listing contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'venue_detail.asp' script not properly sanitizing user-supplied input to the 'VenueID' variable. This may allow an attacker to inject or manipulate SQL queries in the backend database.
Read more...
 
spacer.png, 0 kB
     

© 2008 Intellect Information Technology Pty Ltd, Melbourne, Australia.

This page was loaded in 0.343 seconds.