THE KNOWLEDGE IS THE WORK.
Resources(82)
Netvolution referer header SQL injection vulnerability
CENSUS
A blind SQL injection flaw in Netvolution v2.5.8 (ASP) allows attackers to inject arbitrary SQL commands through the HTTP Referer header. Because the CMS fails to sanitize this header, an unauthenticated attacker can extract database contents, modify site data, inject malicious JavaScript, harvest CMS usernames and...