www.ovosodo.net | Flash XSS - Sql Injections - possible upload of scripts - administrator privileges escalation (system compromise)
(they are not working anymore - check webcaches)
www.ovosodo.net
xss in the requests (simple)
Sql injection (there's no need to write the injection string ... it's very simple)
http://www.ovosodo.net/area_clienti.asp
after *login* it's possible to upload anything that will be available in
http://www.ovosodo.net/images/upload/originali/
www.ovosodo.net
xss in the requests (simple)
Sql injection (there's no need to write the injection string ... it's very simple)
http://www.ovosodo.net/area_clienti.asp
after *login* it's possible to upload anything that will be available in
http://www.ovosodo.net/images/upload/originali/
Comments
Post a Comment