Techno Dreams Products login.asp SQL Injection Vulnerability Security Vulnerability
Description
Some input passed to "login.asp" when logging in isn't properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.
Confirmed in Techno Dreams Announcement, Techno Dreams Guest Book, Techno Dreams Mailing List, Techno Dreams Web Directory. Other products/versions may also be affected.
Impact
The remote attacker can manipulate SQL queries and bypas login.
References
SA17354
Home Page
View entire list of over 400 known Web Application Vulnerabilities and the specific technologies which they target. See Web Vulnerabilities in popular applications such as: WordPress, Tiki Wiki, PHPNuke, PHPMyAdmin, phpBB, Mambo, PHP-Fusion, Mantis, Invision Power Board
Get latest new web vulnerabilities via RSS 
|