bugtraq  

LDF (Default.asp) Sql Injection Vulnerability

Arash . Setayeshi
Mon, 08 Feb 2010 10:03:28 -0800

Product : LDF 

vendor : www.ldf.22.cn

Vulnerable Versions : All 



Default.asp Page has an issue on validating "Page" parameter , It could be 
exploited by attacker & attacker can inject arbitrary Sql Commands



http://www.example.com/[ldf path]/default.asp?page=[SQL COMMAND]



  • LDF (Default.asp) Sql Injection Vulnerability Arash . Setayeshi