Home / os / wince

Contrexx CMS egov moudle OnlineDesk SQL injection

Posted on 30 November -0001

<HTML><HEAD><TITLE>Contrexx CMS egov moudle OnlineDesk SQL injection</TITLE><META http-equiv="Content-Type" content="text/html; charset=utf-8"></HEAD><BODY>Sql Injection in id parameter: http://site/index.php?section=egov&cmd=...&id=[sql query] Demo: --------------------------------------------------------------- https://www.agilityinsights.com/en/index.php?section=egov&cmd=detail&id=22[sqli] http://www.ecm4you.ch/index.php?section=egov&cmd=detail&id=3[sqli] ... --------------------------------------------------------------- </BODY></HTML>

 

TOP