The OpenNET Project
 
Search (keywords):  SOFT ARTICLES TIPS & TRICKS SECURITY
LINKS NEWS MAN DOCUMENTATION


[HSC Security Group] ASP Inline Corporate Calendar SQL injection


<< Previous INDEX Search src Set bookmark Go to bookmark Next >>
Date: 3 May 2005 16:39:32 -0000
From: Zinho <zinho@hackerscenter.com.>
To: [email protected]
Subject: [HSC Security Group] ASP Inline Corporate Calendar SQL injection
X-Virus-Scanned: antivirus-gw at tyumen.ru



Hackers Center Security Group (http://www.hackerscenter.com/)         
Zinho's Security Advisory          

Desc: SQL injection : ASP Inline Corporate Calendar
Risk: Medium

The Corporate Calendar is a nice asp script to manage a calendar shared by users. It has been downloaded by thousands people, and it is considered one of the most successful asp script at hotscripts.com

Multiple sql injections affect ASP Inline Corporate Calendar:

POC:

Calendar/defer.asp?Event_ID='&Occurr_ID=0
or
Calendar/details.asp?Event_ID='


Vendor has been contacted 10 days ago. Noone replied. 



Author:          
Zinho is webmaster and founder of http://www.hackerscenter.com ,       
Security research   portal        
Secure Web Hosting Companies Reviewed:       
http://www.securityforge.com/web-hosting/secure-web-hosting.asp       

zinho-no-spam @ hackerscenter.com 


<< Previous INDEX Search src Set bookmark Go to bookmark Next >>



Партнёры:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
Хостинг:

Закладки на сайте
Проследить за страницей
Created 1996-2025 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру