source: https://www.securityfocus.com/bid/16085/info Multiple Products by Web Wiz are prone to an SQL injection vulnerability. Successful exploitation can allow an attacker to bypass authentication and gain unauthorized access to a site. Attacks may also result in disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation. Web Wiz Site News 3.06 for Access 2000 and Access 97, Web Wiz Journal 1.0 for Access 2000 and Access 97, Web Wiz Polls 3.06 for Access 2000 and Access 97, Web Wiz Database Login 1.71 for Access 2000 and Access 97 are vulnerable to this issue. Prior versions are reportedly affected as well.
Discovery and exploit by devil_box [at} kapda.ir
Kapda - Security Science Researchers Institute of Iran
Discovery and exploit by devil_box [at} kapda.ir