This is a writeup describing a SQL injection vulnerability in DmxReady Faqs Manager v1.2. The vulnerability is located in the 'ItemID' parameter of the 'update.asp' page, allowing attackers to inject malicious SQL queries.
Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target:DmxReady Faqs Manager v1.2
No auth needed
Prerequisites:Access to the vulnerable 'update.asp' page