WHID 2005-21: Insufficient authentication on USC admissions site allowed access to applicants data

Attack Information
WHID ID: 
2005-21
Attack Method: 
Attack Method: 
Attack Method: 
Outcome Information
Outcome: 

A person who discovered an SQL injection vulnerability in a USC system and informed security focus about the flaw was criminally charged with breaking into the system.

Additional information: