[<prev] [next>] [day] [month] [year] [list]
Message-ID: <20071023220448.30371.qmail@securityfocus.com>
Date: 23 Oct 2007 22:04:48 -0000
From: Joseph.giron13@...il.com
To: bugtraq@...urityfocus.com
Subject: Aleris Software Systems Web Publisher Calendar SQL injection
http://www.alerisdata.com/articles/home.asp
There exists an SQL injection vulnerability within the calendar section of a Aleris Software Systems web publisher. It seems thats Aleris uses this same calendar with every site they make that utilizes the publisher.
www.example.com/calendar/page.asp?mode=1%20union%20all%20select%201,2,3,4,5,6%20FROM%20users--
I reported this to aleris and am awaiting a response. No fix yet.
Powered by blists - more mailing lists