#Aria-Security Team Advisory # # #Original Advisory : http://aria-security.net/advisory/igwad.txt #----------------------------------------------------------- #Software: Image gallery with Access Database #Method : SQL Injection # #PoC: #http://target/path/dispimage.asp?id=[SQL Injection] #http://target/path/default.asp?page=2&order=[SQL Injection] #http://target/path/default.asp?page=[SQL INJECTION]&order=id # #Contact: Advisory@aria-security.net