[<prev] [next>] [day] [month] [year] [list]
Message-ID: <20051016171755.17794.qmail@securityfocus.com>
Date: 16 Oct 2005 17:17:55 -0000
From: ali202@...termail.com
To: bugtraq@...urityfocus.com
Subject: Re: Aenovo Multiple Vulnerabilities (Patch)
Patch :
[1]
In "user/control.asp"
Find this :
---------------------------------
pword = Trim(request("password"))
---------------------------------
Replace with this:
---------------------------------
pword = replace(Trim(request("password")),"'","''")
---------------------------------
[2]
In "incs\searchdisplay.asp"
Find this:
---------------------------------
strSQL = request("strSQL")
---------------------------------
Replace with this:
---------------------------------
strSQL = ""
---------------------------------
<ali202>
Powered by blists - more mailing lists