A SQL injection vulnerability has been found in the search.asp script of WebWizForum.
cead45ff35294fdd3b96eea233a7ef20ecfb57a70f0706f879b2c00a0b636710
WebWizForum
aLMaSTeR HaCKeR .. SQL FOunder - | almaster@hotmail.com|-
Gr33tz :-
To Evil Hacker - Kuwaiti Hacker - Devil-00 &..... all members in Lezr.com , securityGurus[dot]com.........
SQL In search.asp:
http://www.site.com/forum/search.asp?KW=|SQL|
Error:
Microsoft OLE DB Provider for SQL Server error '80040e14'
Incorrect syntax near the keyword 'ORDER'.
/forum/search.asp, line 356
TEST:
http://www.shura.gov.bh/forum/search.asp?KW=|SQL|
By aLMaSTeR HaCKeR