Community-Credit.com | NonProfitWays.com | SOAPitstop.com   Skin:   
      User: Not logged in 
Home
Newsletter Signup
XSLT Library
Latest XML Blogs
Featured Examples
Presentations
Featured Articles
Book Chapters
Training Courses
Events
NewsGroups
 
Discussions
Examples
Tutorials
Tools
Articles
Resources
Websites
 
Sign In
My Profile
My Articles
My Examples
My Favorites
My Resources
Add a Resource
Logout
 
About Me
My Blog
HeadGeek Articles
Talking Portfolio
Resume
Pictures
World Trip Pics

Add this resource to your collection of Favorites...

Title:

Microsoft SQL Server SQLXML XML tag script injection

 

Description:

Microsoft SQLXML, included as part of Microsoft SQL Server 2000 Gold or available as a separate add-on component for SQL Server, could allow a remote attacker to execute arbitrary script on the system, caused by improper validation of the "Root" parameter in an XML SQL query. SQLXML is a component used to exchange Extensible Markup Language (XML) data with a SQL server. A remote attacker could include malicious script within the "Root" parameter of an XML SQL query. This would allow the attacker to create a link on a Web page that calls a vulnerable XML SQL query. After the victim clicks the link, the script would be executed in the victim's Web browser within the security context of the local Intranet Zone, once a reply is received from the SQL Server running the SQLXML component.

 

URL:

http://xforce.iss.net/xforce/xfdb/9329



 
 
Fans of "The Office"
Dwight Bobbleheads are here!

  “It's me! I'm the bobblehead! Yes!”



Advertise on XMLPitstop

Advertise on XMLPitstop


EggHead Cafe
Web Servicee development
DotNetSlackers
Discount ink cartridges
buy professional hollywood quality halloween costumes
premiere global
halloween masks
chicago web design
Alojamiento de Web
UK Web Hosting
AXIS IP Security Cameras
Diesel sunglasses
Video Surveillance
VoIP Internettelefonie AT

3,854 Total Members
14 members(last 30 days)
2 members(last 7 days)
0 members(today)

1,942 Total Discussions
3 Posts(last 30 days)
1 Posts(last 7 days)
0 Posts(today)

47,487 Total Blog Posts
0 Blogs(last 30 days)
0 Blogs(last 7 days)
0 Blogs(today)

8,699 Newsgroup Posts
0 Posts(last 30 days)
0 Posts(last 7 days)
0 Posts(today)

14,091 Total Resources
6 Resources(last 30 days)
0 Resources(last 7 days)
0 Resources(today)