The OpenNET Project
 
Search (keywords):  SOFT ARTICLES TIPS & TRICKS SECURITY
LINKS NEWS MAN DOCUMENTATION


aspReady FAQ - open for SQL-injections


<< Previous INDEX Search src Set bookmark Go to bookmark Next >>
Date: 6 Oct 2005 17:13:19 -0000
From: [email protected]
To: [email protected]
Subject: aspReady FAQ  -  open for SQL-injections
X-Virus-Scanned: antivirus-gw at tyumen.ru

The free, open source project called "aspReady FAQ" is open for SQL-injection. 

This results is admin access with the ability change/delete the entire database.

An example on SQL-inject that works could be:
1'or'1'='1


After doing a google search, I've found out that some companies are actually using this free aspReady FAQ. 

Credits to: Preben Nylokken


The system can be found at:
http://pscode.com/vb/scripts/ShowCode.asp?txtCodeId=9055&lngWId=4

Live sample can be found and tested on:
www.itsikkerhet.com/db/faq

- Preben Nyloekken

<< Previous INDEX Search src Set bookmark Go to bookmark Next >>



Партнёры:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
Хостинг:

Закладки на сайте
Проследить за страницей
Created 1996-2025 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру