Deprecated: The each() function is deprecated. This message will be suppressed on further calls in /home/zhenxiangba/zhenxiangba.com/public_html/phproxy-improved-master/index.php on line 456
Aleris Software Systems Web Publisher Calendar SQL injection
[go: Go Back, main page]


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Aleris Software Systems Web Publisher Calendar SQL injection




http://www.alerisdata.com/articles/home.asp

There exists an SQL injection vulnerability within the calendar section of a 
Aleris Software Systems web publisher. It seems thats Aleris uses this same 
calendar with every site they make that utilizes the publisher.

www.example.com/calendar/page.asp?mode=1%20union%20all%20select%201,2,3,4,5,6%20FROM%20users--

I reported this to aleris and am awaiting a response. No fix yet.