SecurityTeam US
 
 Welcome to SecurityTeam US
 Monday, February 06 2012 @ 12:48 PM EST

ASP Virtual News Manager "password" SQL Injection Vulnerability

   
Web Scriptslast samurai has reported a vulnerability in ASP Virtual News Manager, which can be exploited by malicious people to conduct SQL injection attacks.

Input passed to the "password" field in "admin_login.asp" isn't properly sanitized before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.

SOFTWARE:
ASP Virtual News Manager 1.x

SOLUTION:
Edit the source code to ensure that input is properly sanitized.

PROVIDED AND/OR DISCOVERED BY:
last samurai

ORIGINAL ADVISORY:
http://www.under9round.com/avn13.txt

VERIFY ADVISORY:
http://secunia.com/advisories/15346/

Secunia Security Advisories

 

What's Related

Story Options

ASP Virtual News Manager "password" SQL Injection Vulnerability | 0 comments | Create New Account
The following comments are owned by whomever posted them. This site is not responsible for what they say.
 Copyright © 2012 SecurityTeam US
 All trademarks and copyrights on this page are owned by their respective owners.
  Get Firefox!
Dedicated Servers
Created this page in 0.15 seconds