June 26, 2008
1:12 am

Microsoft is aware of a recent escalation in a class of attacks targeting Web sites that use Microsoft ASP and ASP.NET technologies but do not follow best practices for secure Web application development. These SQL injection attacks do not exploit a specific software vulnerability, but instead target Web sites that do not follow secure coding practices for accessing and manipulating data stored in a relational database. When a SQL injection attack succeeds, an attacker can compromise data stored in these databases and possibly execute remote code. Clients browsing to a compromised server could be forwarded unknowingly to malicious sites that may install malware on the client machine.

Mitigating Factors: This vulnerability is not exploitable in Web applications that follow generally accepted best practices for secure Web application development by verifying user data input.

Full Article

Loading

Contextual Related Posts:

No comment yet

Leave a comment »

  1. Pingback from
    1
    injection sites says:July 22nd, 2008 at 6:52 am

    [...] [...]

Leave a Response

Comment Preview
« Windows Server 2008 Hyper-V and BitLocker Drive EncryptionExchange Server 2007: Sample transport agent, add the name of the group to subject line »
Feed Icon

Subscribe via RSS or email: