SQL injection vulnerability in bus_details.asp in Dragon Business Directory - Pro (aka Dragon Internet Business Search Directory - Pro) 3.01.12 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter.
Link | Tags |
---|---|
https://www.exploit-db.com/exploits/2992 | exploit |
http://secunia.com/advisories/23523 | vendor advisory third party advisory exploit |
http://www.securityfocus.com/bid/21747 | vdb entry exploit |
http://www.vupen.com/english/advisories/2006/5152 | vdb entry |