vendor site:http://www.dotnetindex.com/ product:Active News Manager bug:injection sql risk:medium injection sql (get) http://site.com/activenews/activeNews_categories.asp?catID='[sql] http://site.com/activeNews_comments.asp?articleID='[sql] injection sql(post) : in the search engine: /activenews/activenews_search.asp variables : query='[sql] ( or post your query into the search engine ..) laurent gaffié & benjamin mossé http://s-a-p.ca/ contact: saps.audit@gmail.com