Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:15187
HistoryNov 22, 2006 - 12:00 a.m.

Link Exchange Lite [injection sql]

2006-11-2200:00:00
vulners.com
19

vendor site: http://softacid.net/
product:Link Exchange Lite
bug: injection sql
risk : high

injection sql (post) :
/search.asp
post your sql query into the search engine field

injection sql (get):
/linkslist.asp?psearch='[sql]

laurent gaffié & benjamin mossé
http://s-a-p.ca/
contact: [email protected]