Aleris Software Systems Web Publisher Calendar SQL injection

看板Bugtraq作者時間18年前 (2007/10/24 23:10), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/1
http://www.alerisdata.com/articles/home.asp There exists an SQL injection vulnerability within the calendar section of a Aleris Software Systems web publisher. It seems thats Aleris uses this same calendar with every site they make that utilizes the publisher. www.example.com/calendar/page.asp?mode=1%20union%20all%20select%201,2,3,4,5,6%20FROM%20users-- I reported this to aleris and am awaiting a response. No fix yet.
文章代碼(AID): #177s1u00 (Bugtraq)